CVE-2023-50919
CRITICAL EXPLOITEDGL.iNet Unauthenticated Remote Command Execution via the logread module.
Title source: metasploitExploitation Summary
CVE-2023-50919 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit, including a Metasploit module exploits/linux/http/glinet_unauth_rce_cve_2023_50445.
AI-analyzed exploit summary This Metasploit module exploits CVE-2023-50445, a command injection vulnerability in GL.iNet devices, chained with CVE-2023-50919 for authentication bypass. It allows unauthenticated remote command execution via the logread module.
Description
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Exploits (1)
This Metasploit module exploits CVE-2023-50445, a command injection vulnerability in GL.iNet devices, chained with CVE-2023-50919 for authentication bypass. It allows unauthenticated remote command execution via the logread module.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H