An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.