Cyber Resilience

CVE-2024-28077

Gl-Inet Mt6000 Firmware 4.5.6

Published
26 August 2024
Modified
14 March 2025
Patch / advisory
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0043 36th percentile
Risk Priority 57 floored blend · peak EPSS

Summary

CVE-2024-28077 is a high-severity an unspecified weakness vulnerability in Gl-Inet Mt6000 Firmware. Its CVSS base score is 7.5 (High).

Operationally, ranked at the 36th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special…

more

characters (such as half parentheses or square brackets), one can call the login interface and cause the session-management program to crash, resulting in customers being unable to log into their devices. This affects MT6000 4.5.6, XE3000 4.4.5, X3000 4.4.6, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-V2 4.3.10, and XE300 4.3.16.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-45263Same product: Gl-Inet A1300
CVE-2024-45259Same product: Gl-Inet A1300
CVE-2024-45260Same product: Gl-Inet A1300
CVE-2024-45262Same product: Gl-Inet A1300
CVE-2024-45261Same product: Gl-Inet A1300
CVE-2024-27356Same product: Gl-Inet A1300
CVE-2024-39225Same product: Gl-Inet A1300
CVE-2024-39229Same product: Gl-Inet A1300
CVE-2024-39228Same product: Gl-Inet A1300
CVE-2024-39226Same product: Gl-Inet A1300

Affected Assets

gl-inet
mt6000 firmware
4.5.6
gl-inet
x3000 firmware
4.4.6
gl-inet
xe3000 firmware
4.4.4
gl-inet
a1300 firmware
4.5.0
gl-inet
ax1800 firmware
4.5.0
gl-inet
axt1800 firmware
4.5.0
gl-inet
mt2500 firmware
4.5.0
gl-inet
mt3000 firmware
4.5.0
gl-inet
xe300 firmware
4.3.16
gl-inet
x750 firmware
4.3.7
+8 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References