CyberRota Analysis
AI-GeneratedA heap-based buffer overflow vulnerability exists in the APPS-NAS Module's nas-web.get_file_list function across several GL.iNet router models, allowing for remote exploitation. Successful attacks could lead to unauthorized access or execution of arbitrary code, posing a risk to device integrity and network security. Organizations using the affected router models should prioritize patching this vulnerability to mitigate potential threats.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.