GL.iNet Vulnerabilities and Affected Products
Vulnerabilities associated with AXT1800.
Products
Clear product- GL-MT300016 vulnerabilities
- MT30005 vulnerabilities
- MT60005 vulnerabilities
- AX18004 vulnerabilities
- MT25004 vulnerabilities
- A13003 vulnerabilities
- AR300M3 vulnerabilities
- AXT18003 vulnerabilities
- GL-A1300 Slate Plus3 vulnerabilities
- GL-AR300M Shadow3 vulnerabilities
- GL-AR300M16 Shadow3 vulnerabilities
- GL-AR750 Creta3 vulnerabilities
- GL-AR750S-EXT Slate3 vulnerabilities
- GL-AX1800 Flint3 vulnerabilities
- GL-AXT1800 Slate AX3 vulnerabilities
- GL-B1300 Convexa-B3 vulnerabilities
- GL-B3000 Marble3 vulnerabilities
- GL-BE3600 Slate 73 vulnerabilities
- GL-E7503 vulnerabilities
- GL-E750V2 Mudi3 vulnerabilities
- GL-MT1300 Beryl3 vulnerabilities
- GL-MT2500 Brume 23 vulnerabilities
- GL-MT3000 Beryl AX3 vulnerabilities
- GL-MT300N-V2 Mango3 vulnerabilities
- GL-MT6000 Flint 23 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
GL.iNet XE3000 glnassys hard-coded keyA flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised. | CVSS2.3v4.0 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-50920MEDIUM | An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authentication or access control measures. Attackers can impersonate legitimate users or perform unauthorized actions. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B… CWE-384Jan 12, 2024 | CVSS5.5v3.1 | EPSS0.196% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-50445HIGH | gl-inet gl-mt1300_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the get_system_log and get_crash_log functions of the logread module, as well as the upgrade_online function of the upgrade module. | CVSS7.8v3.1 | EPSS9.12% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |