CVE-2025-67091
Unknown Unknown - Not Provided
Privilege Escalation via Shell Redirection in GL.iNet AX1800 Opkg Script

Publication date: 2026-01-08

Last updated on: 2026-01-08

Assigner: MITRE

Description
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-08
Last Modified
2026-01-08
Generated
2026-06-16
AI Q&A
2026-01-08
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
gl.inet gl.inet_ax1800 From 4.6.4 (inc) to 4.6.8 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-377 Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in GL.iNet AX1800 versions 4.6.4 and 4.6.8 within a custom opkg wrapper script located at /usr/libexec/opkg-call. The script runs with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory, which can be exploited.

Impact Analysis

Because the vulnerable script runs with root privileges and uses a world-writable directory for lock file creation, an attacker could potentially exploit this to escalate privileges or interfere with package management, leading to unauthorized actions or compromise of the device.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-67091. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart