Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the get_system_log and get_crash_log functions of the logread module, as well as the upgrade_online function of the upgrade module.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
History
21 Nov 2024, 08:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/176708/GL.iNet-Unauthenticated-Remote-Command-Execution.html - | |
References | () https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Using%20Shell%20Metacharacter%20Injection%20via%20API.md - Exploit, Third Party Advisory |
03 Jul 2024, 01:42
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 |
24 Jan 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
05 Jan 2024, 14:37
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:gl-inet:gl-axt1800_firmware:4.4.6:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-b1300:-:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-ar300m:-:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-b1300_firmware:4.3.7:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-ax1800:-:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-ax1800_firmware:4.4.6:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-mt3000_firmware:4.4.6:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-mt2500:-:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-ar300m_firmware:4.3.7:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-mt1300:-:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-a1300:-:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-a1300_firmware:4.4.6:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-ar750s_firmware:4.3.7:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-mt6000_firmware:4.5.0:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-mt6000:-:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-mt1300_firmware:4.3.7:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-mt300n-v2_firmware:4.3.7:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-ar750_firmware:4.3.7:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-ar750s:-:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-axt1800:-:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-mt300n-v2:-:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:gl-mt2500_firmware:4.4.6:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-ar750:-:*:*:*:*:*:*:* cpe:2.3:h:gl-inet:gl-mt3000:-:*:*:*:*:*:*:* |
|
References | () https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Using%20Shell%20Metacharacter%20Injection%20via%20API.md - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-78 | |
First Time |
Gl-inet gl-ar300m Firmware
Gl-inet gl-ar750s Firmware Gl-inet gl-axt1800 Gl-inet gl-ar300m Gl-inet gl-mt300n-v2 Firmware Gl-inet gl-ar750s Gl-inet gl-mt3000 Gl-inet gl-b1300 Gl-inet gl-mt2500 Firmware Gl-inet gl-a1300 Firmware Gl-inet gl-axt1800 Firmware Gl-inet gl-mt2500 Gl-inet gl-ax1800 Firmware Gl-inet gl-mt6000 Gl-inet gl-mt1300 Gl-inet gl-mt3000 Firmware Gl-inet gl-mt300n-v2 Gl-inet gl-mt1300 Firmware Gl-inet gl-mt6000 Firmware Gl-inet gl-ax1800 Gl-inet Gl-inet gl-ar750 Firmware Gl-inet gl-a1300 Gl-inet gl-b1300 Firmware Gl-inet gl-ar750 |
28 Dec 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-28 05:15
Updated : 2024-11-21 08:37
NVD link : CVE-2023-50445
Mitre link : CVE-2023-50445
CVE.ORG link : CVE-2023-50445
JSON object : View
Products Affected
gl-inet
- gl-mt1300_firmware
- gl-mt6000
- gl-ar300m
- gl-mt3000
- gl-mt6000_firmware
- gl-ar750s
- gl-ar300m_firmware
- gl-a1300_firmware
- gl-mt2500
- gl-mt300n-v2_firmware
- gl-ax1800_firmware
- gl-a1300
- gl-b1300
- gl-ar750_firmware
- gl-mt1300
- gl-ax1800
- gl-axt1800_firmware
- gl-ar750s_firmware
- gl-b1300_firmware
- gl-mt2500_firmware
- gl-mt300n-v2
- gl-ar750
- gl-mt3000_firmware
- gl-axt1800