CVE Vulnerabilities

CVE-2025-50753

Execution with Unnecessary Privileges

Published: Aug 26, 2025 | Modified: Aug 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command deviceinfo show file is supposed to be used from restricted shell to show files and directories. By providing /bin/sh (quotes included) to the argument of this command will drop a root shell.

Weakness

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Potential Mitigations

References