AR300M
by Gl Inet
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46456 | Cri | 0.66 | 9.8 | 0.25 | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality. | ||
| CVE-2023-46454 | Cri | 0.66 | 9.8 | 0.23 | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality. | ||
| CVE-2023-46455 | Hig | 0.53 | 7.5 | 0.47 | Dec 12, 2023 | In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality. |
- risk 0.66cvss 9.8epss 0.25
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
- risk 0.66cvss 9.8epss 0.23
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.
- risk 0.53cvss 7.5epss 0.47
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.