VYPR

GL-AR300M

by Gl Inet

CVEs (4)

  • CVE-2023-46456CriDec 12, 2023
    risk 0.66cvss 9.8epss 0.25

    In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

  • CVE-2023-46454CriDec 12, 2023
    risk 0.66cvss 9.8epss 0.23

    In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

  • CVE-2023-46453CriMay 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression. For example, this affects version 4.3.7 on GL-MT3000 GL-AR300M GL-B1300…

  • CVE-2023-46455HigDec 12, 2023
    risk 0.53cvss 7.5epss 0.47

    In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.