Junglewise Threat Intelligence

CVE-2025-50753: Mitrastar GPT-2741GNAC-N2 privilege escalation in restricted shell

CVE-2025-50753 · Severity: high · CVSS 8.4 · Published 2025-08-26

Executive brief

Mitrastar GPT-2741GNAC-N2 routers, commonly used in home and small business networking, contain a security flaw that allows users to bypass intended restrictions. By entering a specially formatted command into the device's management interface, a user can gain full administrative (root) control. This could allow an attacker with basic access to the device to intercept network traffic, modify system settings, or compromise the security of the entire local network.

Technical details

Mitrastar GPT-2741GNAC-N2 devices provide a restricted shell via SSH, typically accessible using credentials found on the physical device sticker. A privilege escalation vulnerability exists in the 'deviceinfo show file' command due to improper input validation. By passing a specific argument containing a newline character and a shell path (e.g., "\n/bin/sh"), the restricted environment fails to sanitize the input, allowing the execution of an interactive shell with root privileges. This is classified as Execution with Unnecessary Privileges (CWE-250). An attacker with access to the restricted 'support' user account can achieve full system compromise.

Affected products

  • Mitrastar GPT-2741GNAC-N2

Timeline

  • 2025-08-26: disclosed
  • 2025-08-26: advisory

References