Vulnerability Description
An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a crontab-formatted file to a specific directory and waiting for its execution. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-Mt1300 Firmware | 4.3.7 |
| Gl-Inet | Gl-Mt1300 | - |
| Gl-Inet | Gl-Mt300N-V2 Firmware | 4.3.7 |
| Gl-Inet | Gl-Mt300N-V2 | - |
| Gl-Inet | Gl-Ar750S Firmware | 4.3.7 |
| Gl-Inet | Gl-Ar750S | - |
| Gl-Inet | Gl-Ar750 Firmware | 4.3.7 |
| Gl-Inet | Gl-Ar750 | - |
| Gl-Inet | Gl-Ar300M Firmware | 4.3.7 |
| Gl-Inet | Gl-Ar300M | - |
| Gl-Inet | Gl-B1300 Firmware | 4.3.7 |
| Gl-Inet | Gl-B1300 | - |
| Gl-Inet | Gl-Mt6000 Firmware | 4.5.0 |
| Gl-Inet | Gl-Mt6000 | - |
| Gl-Inet | Gl-A1300 Firmware | 4.4.6 |
| Gl-Inet | Gl-A1300 | - |
| Gl-Inet | Gl-Ax1800 Firmware | 4.4.6 |
| Gl-Inet | Gl-Ax1800 | - |
| Gl-Inet | Gl-Axt1800 Firmware | 4.4.6 |
| Gl-Inet | Gl-Axt1800 | - |
Related Weaknesses (CWE)
References
- https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Remote%20code%20execution%ExploitThird Party Advisory
- https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Remote%20code%20execution%ExploitThird Party Advisory
FAQ
What is CVE-2023-50922?
CVE-2023-50922 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a crontab-formatted file to a specific directory...
How severe is CVE-2023-50922?
CVE-2023-50922 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-50922?
Check the references section above for vendor advisories and patch information. Affected products include: Gl-Inet Gl-Mt1300 Firmware, Gl-Inet Gl-Mt1300, Gl-Inet Gl-Mt300N-V2 Firmware, Gl-Inet Gl-Mt300N-V2, Gl-Inet Gl-Ar750S Firmware.