CyberRota Analysis
AI-GeneratedThe GL-iNet GL-MT3000 devices running firmware versions up to 4.4.5 are vulnerable due to a command injection flaw in the wg-server.generate_publickey function, which can be exploited remotely by manipulating the private_key argument. This critical vulnerability, with a CVSS score of 9.8, poses a significant risk as it allows attackers to execute arbitrary commands on the affected devices. Organizations using these devices should prioritize immediate updates or mitigations to safeguard their networks against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.