Executive brief
The MitraStar GPT-2741GNAC-N2-SV router's administrative panel includes ping and other diagnostic utilities that are vulnerable to command injection. An authenticated user can bypass client-side validation and inject arbitrary OS commands through a crafted request, allowing them to read sensitive files, modify configuration, and gain unauthorized shell access with elevated privileges on the router.
Technical details
This is a classic command injection vulnerability in the /cgi-bin/device-management-utilities-internet.cgi endpoint. The vulnerability exists because the CGI script uses cgiFormStringNewline() to accept user input without backend validation, accepting IP address parameters that are concatenated directly into OS commands using the semicolon character (;). While the web interface performs IP format validation on the client side, an attacker with valid credentials can bypass this by sending a crafted POST request directly to the endpoint. An authenticated attacker can inject shell metacharacters to execute arbitrary commands, retrieve output via a subsequent GET request to /cgi-bin/device-management-utilities-internet-content.cgi, and escalate to full system compromise by modifying /etc/passwd or other system files. The fix requires implementing server-side input validation using an allowlist approach and invoking system utilities via execve() family functions instead of shell concatenation.
Affected products
- MitraStar GPT-2741GNAC-N2-SV BR_g8.10_1.11(WVK.0)b46
Timeline
- 2026-09-17: disclosed