CVE-2023-46456
CRITICALGL.iNET GL-AR300M <3.216 - Command Injection
Title source: llmDescription
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.1395
EPSS Percentile
94.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-74
Status
published
Products (1)
gl-inet/gl-ar300m_firmware
3.216
Published
Dec 12, 2023
Tracked Since
Feb 18, 2026