CVE-2023-31478
GL.iNet API Endpoint Information Disclosure Vulnerability
Record summary
CVE-2023-31478 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 31, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
gl-s20_firmwareBrowse gl-inet / gl-s20_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHGL.iNET SSID Key DisclosureCVSS 7.5
An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.
Impact
Unauthenticated attackers can retrieve Wi-Fi SSID and password information through the mesh status API endpoint, potentially allowing unauthorized access to the wireless network and intercepting network traffic.
Remediation
Update GL.iNET firmware to version 3.216 or later that requires authentication for the /api/router/mesh/status endpoint and protects Wi-Fi credentials.
Source: ProjectDiscovery