CVE-2025-67091
Unknown Unknown - Not Provided
Privilege Escalation via Shell Redirection in GL.iNet AX1800 Opkg Script

Publication date: 2026-01-08

Last updated on: 2026-01-08

Assigner: MITRE

Description
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-08
Last Modified
2026-01-08
Generated
2026-05-07
AI Q&A
2026-01-08
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
gl.inet gl.inet_ax1800 From 4.6.4 (inc) to 4.6.8 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-377 Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in GL.iNet AX1800 versions 4.6.4 and 4.6.8 within a custom opkg wrapper script located at /usr/libexec/opkg-call. The script runs with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory, which can be exploited.


How can this vulnerability impact me? :

Because the vulnerable script runs with root privileges and uses a world-writable directory for lock file creation, an attacker could potentially exploit this to escalate privileges or interfere with package management, leading to unauthorized actions or compromise of the device.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart