NA

CVE-2023-31471

Published: 10/05/2023 Updated: 18/05/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists on GL.iNet devices prior to 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gl-inet gl-s20_firmware

gl-inet gl-x3000_firmware

gl-inet gl-mt3000_firmware

gl-inet gl-mt2500_firmware

gl-inet gl-mt2500a_firmware

gl-inet gl-axt1800_firmware

gl-inet gl-a1300_firmware

gl-inet gl-ax1800_firmware

gl-inet gl-sft1200_firmware

gl-inet gl-mt1300_firmware

gl-inet gl-e750_firmware

gl-inet gl-mv1000_firmware

gl-inet gl-mv1000w_firmware

gl-inet gl-s10_firmware

gl-inet gl-s200_firmware

gl-inet gl-s1300_firmware

gl-inet gl-sf1200_firmware

gl-inet gl-b1300_firmware

gl-inet gl-b2200_firmware

gl-inet gl-ap1300_firmware

gl-inet gl-ap1300lte_firmware

gl-inet gl-x1200_firmware

gl-inet gl-x750_firmware

gl-inet gl-x300b_firmware

gl-inet gl-xe300_firmware

gl-inet gl-ar750s_firmware

gl-inet gl-ar750_firmware

gl-inet gl-mifi_firmware

gl-inet gl-mt300n-v2_firmware

gl-inet gl-ar300m_firmware

gl-inet gl-usb150_firmware

gl-inet microuter-n300_firmware