Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-32292 The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials. Comet Gl Rm1 Firmware 1.7.2+ Fix from $1,9502026-03-17 MEDIUM 6.8 CVE-2026-32291 The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the d… Comet Gl Rm1 Firmware 1.8.2+ Fix from $1,6002026-03-17 CRITICAL 9.8 CVE-2026-26793 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attack… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26795 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26791 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26792 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 HIGH 8.8 CVE-2026-26794 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers… Ar300m16 Firmware No fix yet Fix from $1,9502026-03-12 HIGH 8.1 CVE-2025-67089 A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_packa… Gl Axt1800 Firmware No fix yet Fix from $1,9502026-01-08 MEDIUM 6.5 CVE-2025-67091 An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper scri… Ax1800 Firmware No fix yet Fix from $1,6002026-01-08 MEDIUM 5.1 CVE-2025-67090 The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & … Ax1800 Firmware No fix yet Fix from $1,6002026-01-08 HIGH 8.8 CVE-2024-45262 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call met… Mt2500 Firmware 4.6.4+ Fix from $1,9502024-10-24 HIGH 8.8 CVE-2024-45263 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uplo… Mt6000 Firmware 4.6.4+ Fix from $1,9502024-10-24 HIGH 8.0 CVE-2024-45261 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific use… Mt2500 Firmware 4.6.4+ Fix from $1,9502024-10-24 HIGH 8.0 CVE-2024-45260 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized gro… Mt6000 Firmware 4.6.4+ Fix from $1,9502024-10-24 MEDIUM 6.5 CVE-2024-45259 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and … Mt3000 Firmware 4.6.4+ Fix from $1,6002024-10-24 HIGH 7.5 CVE-2024-28077 A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, a… Mt6000 Firmware Mitigation only Fix from $1,9502024-08-26 MEDIUM 5.3 CVE-2024-39229 An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.… Mt6000 Firmware No fix yet Fix from $1,6002024-08-06 CRITICAL 9.8 CVE-2024-39227 GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4… Mt6000 Firmware No fix yet Fix from $2,3002024-08-06 CRITICAL 9.8 CVE-2024-39225EPSS 15% GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4… Mt6000 Firmware No fix yet Fix from $2,3002024-08-06 CRITICAL 9.8 CVE-2024-39226EPSS 21% GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4… Mt6000 Firmware No fix yet Fix from $2,3002024-08-06 CRITICAL 9.8 CVE-2024-39228 GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4… Mt6000 Firmware No fix yet Fix from $2,3002024-08-06 HIGH 7.5 CVE-2024-27356EPSS 24% An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user infor… Mt6000 Firmware Mitigation only Fix from $1,9502024-02-27 CRITICAL 9.8 CVE-2023-50919EPSS 48% An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affect… Gl Ax1800 Firmware No fix yet Fix from $2,3002024-01-12 MEDIUM 5.5 CVE-2023-50920 An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share … Gl Ax1800 Firmware No fix yet Fix from $1,6002024-01-12 CRITICAL 9.8 CVE-2023-50921 An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. T… Gl Mt1300 Firmware Mitigation only Fix from $2,3002024-01-03 HIGH 7.2 CVE-2023-50922 An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploadi… Gl Mt1300 Firmware No fix yet Fix from $1,9502024-01-03 HIGH 7.8 CVE-2023-50445EPSS 9% Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N… Gl Mt1300 Firmware No fix yet Fix from $1,9502023-12-28 CRITICAL 9.8 CVE-2023-46454EPSS 23% In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package in… Gl Ar300m Firmware Mitigation only Fix from $2,3002023-12-12 CRITICAL 9.8 CVE-2023-46456EPSS 25% In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionali… Gl Ar300m Firmware Mitigation only Fix from $2,3002023-12-12 HIGH 7.5 CVE-2023-46455EPSS 47% In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file … Gl Ar300m Firmware Mitigation only Fix from $1,9502023-12-12