Show filters
39 Total Results
Displaying 11-20 of 39
Sort by:
Attacker Value
Unknown

CVE-2023-50922

Disclosure Date: January 03, 2024 (last updated January 11, 2024)
An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a crontab-formatted file to a specific directory and waiting for its execution. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Attacker Value
Unknown

CVE-2023-46456

Disclosure Date: December 12, 2023 (last updated December 15, 2023)
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
Attacker Value
Unknown

CVE-2023-46455

Disclosure Date: December 12, 2023 (last updated December 15, 2023)
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
Attacker Value
Unknown

CVE-2023-46454

Disclosure Date: December 12, 2023 (last updated December 15, 2023)
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.
Attacker Value
Unknown

CVE-2023-47464

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function.
Attacker Value
Unknown

CVE-2023-47463

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.
Attacker Value
Unknown

CVE-2023-47462

Disclosure Date: November 29, 2023 (last updated December 06, 2023)
Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function.
Attacker Value
Unknown

CVE-2023-24261

Disclosure Date: June 21, 2023 (last updated October 08, 2023)
A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.
Attacker Value
Unknown

CVE-2023-33620

Disclosure Date: June 13, 2023 (last updated October 08, 2023)
GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle attack.
Attacker Value
Unknown

CVE-2023-33621

Disclosure Date: June 13, 2023 (last updated October 08, 2023)
GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.