Vulnerability Description
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-S20 Firmware | < 3.216 |
| Gl-Inet | Gl-S20 | - |
| Gl-Inet | Gl-X3000 Firmware | < 3.216 |
| Gl-Inet | Gl-X3000 | - |
| Gl-Inet | Gl-Mt3000 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt3000 | - |
| Gl-Inet | Gl-Mt2500 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt2500 | - |
| Gl-Inet | Gl-Mt2500A Firmware | < 3.216 |
| Gl-Inet | Gl-Mt2500A | - |
| Gl-Inet | Gl-Axt1800 Firmware | < 3.216 |
| Gl-Inet | Gl-Axt1800 | - |
| Gl-Inet | Gl-A1300 Firmware | < 3.216 |
| Gl-Inet | Gl-A1300 | - |
| Gl-Inet | Gl-Ax1800 Firmware | < 3.216 |
| Gl-Inet | Gl-Ax1800 | - |
| Gl-Inet | Gl-Sft1200 Firmware | < 3.216 |
| Gl-Inet | Gl-Sft1200 | - |
| Gl-Inet | Gl-Mt1300 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt1300 | - |
References
- https://github.com/gl-inet/CVE-issues/blob/main/3.215/Abuse_of_Functionality_leaExploit
- https://www.gl-inet.comVendor Advisory
- https://github.com/gl-inet/CVE-issues/blob/main/3.215/Abuse_of_Functionality_leaExploit
- https://www.gl-inet.comVendor Advisory
FAQ
What is CVE-2023-31471?
CVE-2023-31471 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on t...
How severe is CVE-2023-31471?
CVE-2023-31471 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-31471?
Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-S20 Firmware, Gl-Inet Gl-S20, Gl-Inet Gl-X3000 Firmware, Gl-Inet Gl-X3000, Gl-Inet Gl-Mt3000 Firmware.