Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gl Ax1800 Firmware HIGH 8.8
CVE-2023-47464EPSS 23%

Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API…

Fix: 4.5.0+
Fix from $1,950 2023-11-30
Gl Ax1800 Firmware CRITICAL 9.8
CVE-2023-47463

Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted scri…

Fix: 4.5.0+
Fix from $2,300 2023-11-30
Gl Ax1800 Firmware CRITICAL 9.8
CVE-2023-47462

Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing funct…

Fix: after 3.125
Fix from $2,300 2023-11-29
Gl E750 Firmware HIGH 7.2
CVE-2023-24261EPSS 19%

A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.

Fix: 3.216+
Fix from $1,950 2023-06-21
Gl Ar750s Firmware MEDIUM 5.9
CVE-2023-33620

GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle att…

No fix yet
Fix from $1,600 2023-06-13
Gl Ar750s Firmware MEDIUM 5.9
CVE-2023-33621

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. Th…

No fix yet
Fix from $1,600 2023-06-13
Gl S20 Firmware CRITICAL 9.8
CVE-2023-31475EPSS 14%

An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is request…

Fix: 3.216+
Fix from $2,300 2023-05-11
Gl S20 Firmware HIGH 7.5
CVE-2023-31477

A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directo…

Fix: 3.216+
Fix from $1,950 2023-05-11
Gl S20 Firmware CRITICAL 9.8
CVE-2023-31471

An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, suc…

Fix: 3.216+
Fix from $2,300 2023-05-10
Gl S20 Firmware HIGH 7.5
CVE-2023-31478EPSS 30%

An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and ke…

Fix: 3.216+
Fix from $1,950 2023-05-09
Gl S20 Firmware HIGH 7.5
CVE-2023-31472EPSS 20%

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the files…

Fix: 3.216+
Fix from $1,950 2023-05-09
Gl S20 Firmware HIGH 7.5
CVE-2023-31474

An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in …

Fix: 3.216+
Fix from $1,950 2023-05-09
Gl Mv1000w Firmware HIGH 7.5
CVE-2023-31476

An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almo…

Fix: after 3.215
Fix from $1,950 2023-05-09
Gl Mt3000 Firmware CRITICAL 9.8
CVE-2023-29778EPSS 16%

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

Mitigation only
Fix from $2,300 2023-05-02
Goodcloud HIGH 7.4
CVE-2022-44211

In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.

Fix: after 1.0
Fix from $1,950 2022-12-01
Goodcloud MEDIUM 5.9
CVE-2022-44212

In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.

Fix: after 1.0
Fix from $1,600 2022-12-01
Goodcloud MEDIUM 6.5
CVE-2022-42055

Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools…

No fix yet
Fix from $1,600 2022-10-27
Goodcloud MEDIUM 5.4
CVE-2022-42054

Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers t…

No fix yet
Fix from $1,600 2022-10-27
Gl Mt300n V2 Firmware MEDIUM 6.8
CVE-2022-31898EPSS 16%

gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr …

No fix yet
Fix from $1,600 2022-10-27
Gl Ar150 Firmware MEDIUM 6.1
CVE-2021-44148

GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with …

Fix: 3.0+
Fix from $1,600 2021-12-07
Gl Ar300m Lite Firmware HIGH 8.8
CVE-2019-6272EPSS 13%

Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2019-03-21
Gl Ar300m Lite Firmware HIGH 8.8
CVE-2019-6274EPSS 11%

Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified imp…

No fix yet
Fix from $1,950 2019-03-21
Gl Ar300m Lite Firmware HIGH 8.8
CVE-2019-6275EPSS 13%

Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary cod…

No fix yet
Fix from $1,950 2019-03-21
Gl Ar300m Lite Firmware MEDIUM 6.5
CVE-2019-6273EPSS 12%

download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.

No fix yet
Fix from $1,600 2019-03-21