Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26793

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attack…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26795

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26791

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26792

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware HIGH 8.8
CVE-2026-26794

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers…

No fix yet
Fix from $1,950 2026-03-12
Gl Axt1800 Firmware HIGH 8.1
CVE-2025-67089

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_packa…

No fix yet
Fix from $1,950 2026-01-08
Ax1800 Firmware MEDIUM 6.5
CVE-2025-67091

An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper scri…

No fix yet
Fix from $1,600 2026-01-08
Ax1800 Firmware MEDIUM 5.1
CVE-2025-67090

The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & …

No fix yet
Fix from $1,600 2026-01-08
Mt6000 Firmware HIGH 7.5
CVE-2024-28077

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, a…

Mitigation only
Fix from $1,950 2024-08-26
Mt6000 Firmware MEDIUM 5.3
CVE-2024-39229

An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.…

No fix yet
Fix from $1,600 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39227

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39225EPSS 15%

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39226EPSS 21%

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39228

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware HIGH 7.5
CVE-2024-27356EPSS 24%

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user infor…

Mitigation only
Fix from $1,950 2024-02-27
Gl Ax1800 Firmware CRITICAL 9.8
CVE-2023-50919EPSS 48%

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affect…

No fix yet
Fix from $2,300 2024-01-12
Gl Ax1800 Firmware MEDIUM 5.5
CVE-2023-50920

An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share …

No fix yet
Fix from $1,600 2024-01-12
Gl Mt1300 Firmware CRITICAL 9.8
CVE-2023-50921

An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. T…

Mitigation only
Fix from $2,300 2024-01-03
Gl Mt1300 Firmware HIGH 7.2
CVE-2023-50922

An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploadi…

No fix yet
Fix from $1,950 2024-01-03
Gl Mt1300 Firmware HIGH 7.8
CVE-2023-50445EPSS 9%

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N…

No fix yet
Fix from $1,950 2023-12-28
Gl Ar300m Firmware CRITICAL 9.8
CVE-2023-46454EPSS 23%

In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package in…

Mitigation only
Fix from $2,300 2023-12-12
Gl Ar300m Firmware CRITICAL 9.8
CVE-2023-46456EPSS 25%

In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionali…

Mitigation only
Fix from $2,300 2023-12-12
Gl Ar300m Firmware HIGH 7.5
CVE-2023-46455EPSS 47%

In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file …

Mitigation only
Fix from $1,950 2023-12-12
Gl Ar750s Firmware MEDIUM 5.9
CVE-2023-33620

GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle att…

No fix yet
Fix from $1,600 2023-06-13
Gl Ar750s Firmware MEDIUM 5.9
CVE-2023-33621

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. Th…

No fix yet
Fix from $1,600 2023-06-13
Gl Mt3000 Firmware CRITICAL 9.8
CVE-2023-29778EPSS 16%

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

Mitigation only
Fix from $2,300 2023-05-02
Goodcloud MEDIUM 6.5
CVE-2022-42055

Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools…

No fix yet
Fix from $1,600 2022-10-27
Goodcloud MEDIUM 5.4
CVE-2022-42054

Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers t…

No fix yet
Fix from $1,600 2022-10-27
Gl Mt300n V2 Firmware MEDIUM 6.8
CVE-2022-31898EPSS 16%

gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr …

No fix yet
Fix from $1,600 2022-10-27
Gl Ar300m Lite Firmware HIGH 8.8
CVE-2019-6272EPSS 13%

Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2019-03-21