Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxm8-fmqv-9x7q

Опубликовано: 08 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the plugins.install_package RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the plugins.install_package RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

EPSS

Процентиль: 54%
0.00313
Низкий

8.1 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

EPSS

Процентиль: 54%
0.00313
Низкий

8.1 High

CVSS3

Дефекты

CWE-77