CVE-2025-2850
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Apr 26, 2025
Updated: Apr 29, 2025
CWE ID 285
CWE ID 266
Summary
CVE-2025-2850 is a recently discovered vulnerability affecting multiple GL.iNet routers, including the Slate Plus, Shadow, Creta, and others. The issue lies within the Download Interface component and has been assessed as problematic. The vulnerability allows unauthorized manipulation, leading to improper authorization. Affected devices should be upgraded to mitigate this risk. Specific details regarding the impact and exploit of the vulnerability remain unknown.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gl-B3000 Marble
- Gl-X300B Collie
- Gl-B1300 Convexa-B
- GL-AXT1800 Slate AX
- GL-AX1800 Flint