Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-47464EPSS 23% Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API… Gl Ax1800 Firmware 4.5.0+ Fix from $1,9502023-11-30 CRITICAL 9.8 CVE-2023-47463 Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted scri… Gl Ax1800 Firmware 4.5.0+ Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-47462 Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing funct… Gl Ax1800 Firmware after 3.125 Fix from $2,3002023-11-29 HIGH 7.2 CVE-2023-24261EPSS 19% A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request. Gl E750 Firmware 3.216+ Fix from $1,9502023-06-21 MEDIUM 5.9 CVE-2023-33620 GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle att… Gl Ar750s Firmware No fix yet Fix from $1,6002023-06-13 MEDIUM 5.9 CVE-2023-33621 GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. Th… Gl Ar750s Firmware No fix yet Fix from $1,6002023-06-13 CRITICAL 9.8 CVE-2023-31475EPSS 14% An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is request… Gl S20 Firmware 3.216+ Fix from $2,3002023-05-11 HIGH 7.5 CVE-2023-31477 A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directo… Gl S20 Firmware 3.216+ Fix from $1,9502023-05-11 CRITICAL 9.8 CVE-2023-31471 An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, suc… Gl S20 Firmware 3.216+ Fix from $2,3002023-05-10 HIGH 7.5 CVE-2023-31478EPSS 30% An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and ke… Gl S20 Firmware 3.216+ Fix from $1,9502023-05-09 HIGH 7.5 CVE-2023-31472EPSS 20% An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the files… Gl S20 Firmware 3.216+ Fix from $1,9502023-05-09 HIGH 7.5 CVE-2023-31474 An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in … Gl S20 Firmware 3.216+ Fix from $1,9502023-05-09 HIGH 7.5 CVE-2023-31476 An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almo… Gl Mv1000w Firmware after 3.215 Fix from $1,9502023-05-09 CRITICAL 9.8 CVE-2023-29778EPSS 16% GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. Gl Mt3000 Firmware Mitigation only Fix from $2,3002023-05-02 HIGH 7.4 CVE-2022-44211 In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings. Goodcloud after 1.0 Fix from $1,9502022-12-01 MEDIUM 5.9 CVE-2022-44212 In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel. Goodcloud after 1.0 Fix from $1,6002022-12-01 MEDIUM 6.5 CVE-2022-42055 Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools… Goodcloud No fix yet Fix from $1,6002022-10-27 MEDIUM 5.4 CVE-2022-42054 Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers t… Goodcloud No fix yet Fix from $1,6002022-10-27 MEDIUM 6.8 CVE-2022-31898EPSS 16% gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr … Gl Mt300n V2 Firmware No fix yet Fix from $1,6002022-10-27 MEDIUM 6.1 CVE-2021-44148 GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with … Gl Ar150 Firmware 3.0+ Fix from $1,6002021-12-07 HIGH 8.8 CVE-2019-6272EPSS 13% Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. Gl Ar300m Lite Firmware No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2019-6274EPSS 11% Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified imp… Gl Ar300m Lite Firmware No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2019-6275EPSS 13% Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary cod… Gl Ar300m Lite Firmware No fix yet Fix from $1,9502019-03-21 MEDIUM 6.5 CVE-2019-6273EPSS 12% download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. Gl Ar300m Lite Firmware No fix yet Fix from $1,6002019-03-21