CVE-2025-2851
CVSS 3.1 Score 8 of 10 (high)
Details
Published Apr 26, 2025
Updated: Apr 29, 2025
CWE ID 119
CWE ID 120
Summary
CVE-2025-2851 is a newly discovered critical vulnerability that affects multiple GL.iNet models, including the Slate Plus, Shadow, Creta, Flint, Brume 2, Beryl AX, and others running on firmware version 4.x. The issue lies within the file plugins.so component of the RPC Handler, resulting in a buffer overflow when an unknown function is manipulated. Upgrading the affected component is strongly advised to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gl-B3000 Marble
- Gl-X300B Collie
- Gl-B1300 Convexa-B
- GL-AXT1800 Slate AX
- GL-AX1800 Flint