CRITICAL · 9.8

CVE-2023-31471

An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on t...

Vulnerability Description

An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Gl-InetGl-S20 Firmware< 3.216
Gl-InetGl-S20-
Gl-InetGl-X3000 Firmware< 3.216
Gl-InetGl-X3000-
Gl-InetGl-Mt3000 Firmware< 3.216
Gl-InetGl-Mt3000-
Gl-InetGl-Mt2500 Firmware< 3.216
Gl-InetGl-Mt2500-
Gl-InetGl-Mt2500A Firmware< 3.216
Gl-InetGl-Mt2500A-
Gl-InetGl-Axt1800 Firmware< 3.216
Gl-InetGl-Axt1800-
Gl-InetGl-A1300 Firmware< 3.216
Gl-InetGl-A1300-
Gl-InetGl-Ax1800 Firmware< 3.216
Gl-InetGl-Ax1800-
Gl-InetGl-Sft1200 Firmware< 3.216
Gl-InetGl-Sft1200-
Gl-InetGl-Mt1300 Firmware< 3.216
Gl-InetGl-Mt1300-

References

FAQ

What is CVE-2023-31471?

CVE-2023-31471 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on t...

How severe is CVE-2023-31471?

CVE-2023-31471 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-31471?

Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-S20 Firmware, Gl-Inet Gl-S20, Gl-Inet Gl-X3000 Firmware, Gl-Inet Gl-X3000, Gl-Inet Gl-Mt3000 Firmware.