CVE-2025-2851

CVSS 3.1 Score 8 of 10 (high)

Details

Published Apr 26, 2025
Updated: Apr 29, 2025
CWE ID 119
CWE ID 120

Summary

CVE-2025-2851 is a newly discovered critical vulnerability that affects multiple GL.iNet models, including the Slate Plus, Shadow, Creta, Flint, Brume 2, Beryl AX, and others running on firmware version 4.x. The issue lies within the file plugins.so component of the RPC Handler, resulting in a buffer overflow when an unknown function is manipulated. Upgrading the affected component is strongly advised to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Gl-B3000 Marble
  • Gl-X300B Collie
  • Gl-B1300 Convexa-B
  • GL-AXT1800 Slate AX
  • GL-AX1800 Flint