Vulnerability Description
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-Mt1300 Firmware | 4.3.7 |
| Gl-Inet | Gl-Mt1300 | - |
| Gl-Inet | Gl-Mt300N-V2 Firmware | 4.3.7 |
| Gl-Inet | Gl-Mt300N-V2 | - |
| Gl-Inet | Gl-Ar750S Firmware | 4.3.7 |
| Gl-Inet | Gl-Ar750S | - |
| Gl-Inet | Gl-Ar750 Firmware | 4.3.7 |
| Gl-Inet | Gl-Ar750 | - |
| Gl-Inet | Gl-Ar300M Firmware | 4.3.7 |
| Gl-Inet | Gl-Ar300M | - |
| Gl-Inet | Gl-B1300 Firmware | 4.3.7 |
| Gl-Inet | Gl-B1300 | - |
| Gl-Inet | Gl-Mt6000 Firmware | 4.5.0 |
| Gl-Inet | Gl-Mt6000 | - |
| Gl-Inet | Gl-A1300 Firmware | 4.4.6 |
| Gl-Inet | Gl-A1300 | - |
| Gl-Inet | Gl-Ax1800 Firmware | 4.4.6 |
| Gl-Inet | Gl-Ax1800 | - |
| Gl-Inet | Gl-Axt1800 Firmware | 4.4.6 |
| Gl-Inet | Gl-Axt1800 | - |
Related Weaknesses (CWE)
References
- https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Add_user_vulnerability.mdThird Party Advisory
- https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Add_user_vulnerability.mdThird Party Advisory
FAQ
What is CVE-2023-50921?
CVE-2023-50921 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4....
How severe is CVE-2023-50921?
CVE-2023-50921 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-50921?
Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-Mt1300 Firmware, Gl-Inet Gl-Mt1300, Gl-Inet Gl-Mt300N-V2 Firmware, Gl-Inet Gl-Mt300N-V2, Gl-Inet Gl-Ar750S Firmware.