Mitrastar's vulnerability footprint concentrates in a narrow set of DSL and wireless networking devices such as the DSL-100HN and GPT-2541GNAC, where the recurring exposure centers on OS command injection and improper default permissions in firmware. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mitrastar over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42165HIGH MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorre | May 3, 2022 | 8.8 | 45 | NO | YES |
CVE-2023-33381HIGH A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authe | Jun 6, 2023 | 7.2 | 35 | NO | NO |
CVE-2017-16523CRITICAL MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalent to root and undocumented. | Nov 3, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-16522HIGH MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by specifying /bin/sh as the command to exec | Nov 3, 2017 | 8.8 | 27 | NO | NO |
CVE-2023-30065HIGH MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the ping function. | May 5, 2023 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mitrastar.
Media articles that mention a CVE ID that affects a product developed by Mitrastar — matched by CVE ID, not by vendor name.