VYPR

GL.iNet

by Gl Inet

CVEs (4)

  • CVE-2023-50919CriJan 12, 2024
    risk 0.71cvss 9.8epss 0.48

    An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7,…

  • CVE-2023-31471CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is…

  • CVE-2023-31478HigMay 9, 2023
    risk 0.51cvss 7.5epss 0.30

    An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.

  • CVE-2023-31477HigMay 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.