HIGH · 7.8

CVE-2023-50445

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4....

Vulnerability Description

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the get_system_log and get_crash_log functions of the logread module, as well as the upgrade_online function of the upgrade module.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Gl-InetGl-Mt1300 Firmware4.3.7
Gl-InetGl-Mt1300-
Gl-InetGl-Mt300N-V2 Firmware4.3.7
Gl-InetGl-Mt300N-V2-
Gl-InetGl-Ar750S Firmware4.3.7
Gl-InetGl-Ar750S-
Gl-InetGl-Ar750 Firmware4.3.7
Gl-InetGl-Ar750-
Gl-InetGl-Ar300M Firmware4.3.7
Gl-InetGl-Ar300M-
Gl-InetGl-B1300 Firmware4.3.7
Gl-InetGl-B1300-
Gl-InetGl-Mt6000 Firmware4.5.0
Gl-InetGl-Mt6000-
Gl-InetGl-A1300 Firmware4.4.6
Gl-InetGl-A1300-
Gl-InetGl-Ax1800 Firmware4.4.6
Gl-InetGl-Ax1800-
Gl-InetGl-Axt1800 Firmware4.4.6
Gl-InetGl-Axt1800-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-50445?

CVE-2023-50445 is a vulnerability with a CVSS score of 7.8 (HIGH). Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4....

How severe is CVE-2023-50445?

CVE-2023-50445 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-50445?

Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-Mt1300 Firmware, Gl-Inet Gl-Mt1300, Gl-Inet Gl-Mt300N-V2 Firmware, Gl-Inet Gl-Mt300N-V2, Gl-Inet Gl-Ar750S Firmware.