An issue was discovered on GL.iNet devices through 4.5.0....
Critical severity
Unreviewed
Published
Jan 3, 2024
to the GitHub Advisory Database
•
Updated Jun 18, 2025
Description
Published by the National Vulnerability Database
Jan 3, 2024
Published to the GitHub Advisory Database
Jan 3, 2024
Last updated
Jun 18, 2025
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
References