Vulnerability Description
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-S20 Firmware | < 3.216 |
| Gl-Inet | Gl-S20 | - |
| Gl-Inet | Gl-X3000 Firmware | < 3.216 |
| Gl-Inet | Gl-X3000 | - |
| Gl-Inet | Gl-Mt3000 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt3000 | - |
| Gl-Inet | Gl-Mt2500 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt2500 | - |
| Gl-Inet | Gl-Mt2500A Firmware | < 3.216 |
| Gl-Inet | Gl-Mt2500A | - |
| Gl-Inet | Gl-Axt1800 Firmware | < 3.216 |
| Gl-Inet | Gl-Axt1800 | - |
| Gl-Inet | Gl-A1300 Firmware | < 3.216 |
| Gl-Inet | Gl-A1300 | - |
| Gl-Inet | Gl-Ax1800 Firmware | < 3.216 |
| Gl-Inet | Gl-Ax1800 | - |
| Gl-Inet | Gl-Sft1200 Firmware | < 3.216 |
| Gl-Inet | Gl-Sft1200 | - |
| Gl-Inet | Gl-Mt1300 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt1300 | - |
Related Weaknesses (CWE)
References
- https://github.com/gl-inet/CVE-issues/blob/main/3.215/Buffer_Overflow.mdExploitThird Party Advisory
- https://justinapplegate.me/2023/glinet-CVE-2023-31475/
- https://www.gl-inet.comVendor Advisory
- https://github.com/gl-inet/CVE-issues/blob/main/3.215/Buffer_Overflow.mdExploitThird Party Advisory
- https://justinapplegate.me/2023/glinet-CVE-2023-31475/
- https://www.gl-inet.comVendor Advisory
FAQ
What is CVE-2023-31475?
CVE-2023-31475 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into...
How severe is CVE-2023-31475?
CVE-2023-31475 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-31475?
Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-S20 Firmware, Gl-Inet Gl-S20, Gl-Inet Gl-X3000 Firmware, Gl-Inet Gl-X3000, Gl-Inet Gl-Mt3000 Firmware.