📦 Gl Ar300m Firmware

by Gl Inet

🔍 What is Gl Ar300m Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-50919

CRITICAL CVSS 9.8 Jan 12, 2024

This CVE describes an NGINX authentication bypass vulnerability in GL.iNet router firmware that allows unauthenticated attackers to execute arbitrary commands. The flaw exists in Lua string pattern ma...

CVE-2023-50921

CRITICAL CVSS 9.8 Jan 3, 2024

This vulnerability allows attackers to invoke the add_user interface in the system module on GL.iNet devices to gain root privileges. It affects multiple GL.iNet router models running firmware version...

CVE-2023-46454

CRITICAL CVSS 9.8 Dec 12, 2023

This vulnerability allows remote attackers to execute arbitrary shell commands on GL.iNET GL-AR300M routers by injecting malicious commands into package names. Attackers can gain full control of affec...

CVE-2023-46456

CRITICAL CVSS 9.8 Dec 12, 2023

This vulnerability allows remote attackers to execute arbitrary shell commands on GL.iNET GL-AR300M routers by exploiting improper input validation in the OpenVPN client file upload functionality. Att...

CVE-2023-31471

CRITICAL CVSS 9.8 May 10, 2023

This vulnerability allows attackers to install arbitrary software on GL.iNet devices by bypassing client-side package verification. It enables remote code execution through the software installation f...

CVE-2023-50922

HIGH CVSS 7.2 Jan 3, 2024

This vulnerability allows attackers who steal the AdminToken cookie to upload malicious crontab files to GL.iNet devices, leading to arbitrary code execution. It affects multiple GL.iNet router models...

CVE-2023-50445

HIGH CVSS 7.8 Dec 28, 2023

This CVE describes a shell injection vulnerability in multiple GL.iNet router models that allows local attackers to execute arbitrary code via specific API functions. Attackers can exploit functions i...

CVE-2023-31478

HIGH CVSS 7.5 May 9, 2023

This vulnerability in GL.iNet devices exposes Wi-Fi configuration details including SSID and encryption keys through an API endpoint. Attackers can retrieve Wi-Fi credentials, potentially gaining unau...

CVE-2023-31472

HIGH CVSS 7.5 May 9, 2023

This CVE describes a command injection vulnerability in GL.iNet devices that allows attackers to create empty files anywhere on the filesystem. The vulnerability affects GL.iNet devices running firmwa...