CVE-2025-2811

CVSS 3.1 Score 5.7 of 10 (medium)

Details

Published Apr 26, 2025
Updated: Apr 29, 2025
CWE ID 1333
CWE ID 400

Summary

CVE-2025-2811 is a vulnerability affecting various GL.iNet models, including the Slate Plus, Shadow, Creta, Flint, AX, Convexa-B, Marble, Slate 7, Mudi, Mango, Beryl, Brume 2, Beryl AX, Flint 2, Opal, Collie, Spitz, Spitz AX, Puli, and Puli AX with the 4.x firmware. The issue lies within the component API, specifically with manipulation of unknown code that results in inefficient regular expression complexity. This vulnerability poses an unspecified risk and requires an immediate upgrade of the affected component to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gl-B3000 Marble
  • Gl-X300B Collie
  • Gl-B1300 Convexa-B
  • GL-AXT1800 Slate AX
  • GL-AX1800 Flint