OS Command Injection in GL.iNet products - CVE-2024-57391
Published: May 12, 2025
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
GL-X750 Spitz
GL-AX1800 Flint
GL-SFT1200 Opal
GL-AR750S-EXT Slate
GL-XE3000 Puli AX
GL-MT1300 Beryl
GL-X3000 Spitz AX
GL-AR300M Shadow
GL-X300B Collie
GL-E750/GL-E750V2 Mudi
GL-A1300 Slate Plus
GL-B3000 Marble
GL-XE300 Puli
GL-MT6000 Flint 2
GL-B1300 Convexa-B
GL-MT3000 Beryl AX
GL-MT2500 Brume 2
GL-MT300N-V2 Mango
GL-AXT1800 Slate AX
GL-AR750 Creta
GL-BE3600 Slate 7
How to mitigate CVE-2024-57391
GL-X750 Spitz - update to 4.3.25
GL-AX1800 Flint - update to 4.7.0
GL-SFT1200 Opal - update to 4.3.25
GL-AR750S-EXT Slate - update to 4.3.25
GL-XE3000 Puli AX - update to 4.7.4
GL-MT1300 Beryl - update to 4.3.25
GL-X3000 Spitz AX - update to 4.7.4
GL-AR300M Shadow - update to 4.3.25
GL-X300B Collie - update to 4.5.22
GL-E750/GL-E750V2 Mudi - update to 4.3.26
GL-A1300 Slate Plus - update to 4.5.22
GL-B3000 Marble - update to 4.5.22
GL-XE300 Puli - update to 4.3.25
GL-MT6000 Flint 2 - update to 4.7.4
GL-B1300 Convexa-B - update to 4.3.25
GL-MT3000 Beryl AX - update to 4.7.4
GL-MT2500 Brume 2 - update to 4.7.4
GL-MT300N-V2 Mango - update to 4.3.25
GL-AXT1800 Slate AX - update to 4.7.0
GL-AR750 Creta - update to 4.3.25
GL-BE3600 Slate 7 - update to 4.7.1