NA

CVE-2023-31471

Published: 10/05/2023 Updated: 18/05/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists on GL.iNet devices prior to 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gl-inet gl-s20 firmware

gl-inet gl-x3000 firmware

gl-inet gl-mt3000 firmware

gl-inet gl-mt2500 firmware

gl-inet gl-mt2500a firmware

gl-inet gl-axt1800 firmware

gl-inet gl-a1300 firmware

gl-inet gl-ax1800 firmware

gl-inet gl-sft1200 firmware

gl-inet gl-mt1300 firmware

gl-inet gl-e750 firmware

gl-inet gl-mv1000 firmware

gl-inet gl-mv1000w firmware

gl-inet gl-s10 firmware

gl-inet gl-s200 firmware

gl-inet gl-s1300 firmware

gl-inet gl-sf1200 firmware

gl-inet gl-b1300 firmware

gl-inet gl-b2200 firmware

gl-inet gl-ap1300 firmware

gl-inet gl-ap1300lte firmware

gl-inet gl-x1200 firmware

gl-inet gl-x750 firmware

gl-inet gl-x300b firmware

gl-inet gl-xe300 firmware

gl-inet gl-ar750s firmware

gl-inet gl-ar750 firmware

gl-inet gl-mifi firmware

gl-inet gl-mt300n-v2 firmware

gl-inet gl-ar300m firmware

gl-inet gl-usb150 firmware

gl-inet microuter-n300 firmware