CVE Feed

    Dashboard / CVE / CVE-2024-28077

    CVE-2024-28077

    A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special characters (such as half parentheses or square brackets), one can call the login interface and cause the session-management program to crash, resulting in customers being unable to log into their devices. This affects MT6000 4.5.6, XE3000 4.4.5, X3000 4.4.6, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-V2 4.3.10, and XE300 4.3.16.

    Published:Aug 26, 2024
    Last Modified:Mar 14, 2025
    EPS:Aug 26, 2024
    EPSS Score:0.00196
    CVSS Score:7.5

    Affected Products

    Vendor
    Gl-inet
    Product
    A1300
    Vendor
    Gl-inet
    Product
    A1300 Firmware
    Vendor
    Gl-inet
    Product
    Ar300m
    Vendor
    Gl-inet
    Product
    Ar300m16
    Vendor
    Gl-inet
    Product
    Ar300m16 Firmware
    Vendor
    Gl-inet
    Product
    Ar300m Firmware
    Vendor
    Gl-inet
    Product
    Ar750
    Vendor
    Gl-inet
    Product
    Ar750 Firmware
    Vendor
    Gl-inet
    Product
    Ar750s
    Vendor
    Gl-inet
    Product
    Ar750s Firmware
    Vendor
    Gl-inet
    Product
    Ax1800
    Vendor
    Gl-inet
    Product
    Ax1800 Firmware
    Vendor
    Gl-inet
    Product
    Axt1800
    Vendor
    Gl-inet
    Product
    Axt1800 Firmware
    Vendor
    Gl-inet
    Product
    B1300
    Vendor
    Gl-inet
    Product
    B1300 Firmware
    Vendor
    Gl-inet
    Product
    Mt1300
    Vendor
    Gl-inet
    Product
    Mt1300 Firmware
    Vendor
    Gl-inet
    Product
    Mt2500
    Vendor
    Gl-inet
    Product
    Mt2500 Firmware
    Vendor
    Gl-inet
    Product
    Mt3000
    Vendor
    Gl-inet
    Product
    Mt3000 Firmware
    Vendor
    Gl-inet
    Product
    Mt300n-v2
    Vendor
    Gl-inet
    Product
    Mt300n-v2 Firmware
    Vendor
    Gl-inet
    Product
    Mt6000
    Vendor
    Gl-inet
    Product
    Mt6000 Firmware
    Vendor
    Gl-inet
    Product
    Sft1200
    Vendor
    Gl-inet
    Product
    Sft1200 Firmware
    Vendor
    Gl-inet
    Product
    X3000
    Vendor
    Gl-inet
    Product
    X3000 Firmware
    Vendor
    Gl-inet
    Product
    X750
    Vendor
    Gl-inet
    Product
    X750 Firmware
    Vendor
    Gl-inet
    Product
    Xe300
    Vendor
    Gl-inet
    Product
    Xe3000
    Vendor
    Gl-inet
    Product
    Xe3000 Firmware
    Vendor
    Gl-inet
    Product
    Xe300 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High