NA

CVE-2023-50920

Published: 12/01/2024 Updated: 19/01/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing malicious users to share session identifiers between different sessions and bypass authentication or access control measures. Attackers can impersonate legitimate users or perform unauthorized actions. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.

Vulnerable Product Search on Vulmon Subscribe to Product

gl-inet gl-ax1800_firmware 4.3.7

gl-inet gl-ax1800_firmware 4.4.6

gl-inet gl-axt1800_firmware 4.3.7

gl-inet gl-axt1800_firmware 4.4.6

gl-inet gl-mt3000_firmware 4.3.7

gl-inet gl-mt3000_firmware 4.4.6

gl-inet gl-mt2500_firmware 4.3.7

gl-inet gl-mt2500_firmware 4.4.6

gl-inet gl-mt6000_firmware 4.3.7

gl-inet gl-mt6000_firmware 4.4.6

gl-inet gl-mt1300_firmware 4.3.7

gl-inet gl-mt1300_firmware 4.4.6

gl-inet gl-mt300n-v2_firmware 4.3.7

gl-inet gl-mt300n-v2_firmware 4.4.6

gl-inet gl-ar750s_firmware 4.3.7

gl-inet gl-ar750s_firmware 4.4.6

gl-inet gl-ar750_firmware 4.3.7

gl-inet gl-ar750_firmware 4.4.6

gl-inet gl-ar300m_firmware 4.3.7

gl-inet gl-ar300m_firmware 4.4.6

gl-inet gl-b1300_firmware 4.3.7

gl-inet gl-b1300_firmware 4.4.6

gl-inet gl-a1300_firmware 4.3.7

gl-inet gl-a1300_firmware 4.4.6