Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Comet Gl Rm1 Firmware HIGH 7.5
CVE-2026-32292

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.

Fix: 1.7.2+
Fix from $1,950 2026-03-17
Comet Gl Rm1 Firmware MEDIUM 6.8
CVE-2026-32291

The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the d…

Fix: 1.8.2+
Fix from $1,600 2026-03-17
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26793

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attack…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26795

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26791

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26792

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware HIGH 8.8
CVE-2026-26794

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers…

No fix yet
Fix from $1,950 2026-03-12
Gl Axt1800 Firmware HIGH 8.1
CVE-2025-67089

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_packa…

No fix yet
Fix from $1,950 2026-01-08
Ax1800 Firmware MEDIUM 6.5
CVE-2025-67091

An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper scri…

No fix yet
Fix from $1,600 2026-01-08
Ax1800 Firmware MEDIUM 5.1
CVE-2025-67090

The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & …

No fix yet
Fix from $1,600 2026-01-08
Mt2500 Firmware HIGH 8.8
CVE-2024-45262

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call met…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
Mt6000 Firmware HIGH 8.8
CVE-2024-45263

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uplo…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
Mt2500 Firmware HIGH 8.0
CVE-2024-45261

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific use…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
Mt6000 Firmware HIGH 8.0
CVE-2024-45260

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized gro…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
Mt3000 Firmware MEDIUM 6.5
CVE-2024-45259

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and …

Fix: 4.6.4+
Fix from $1,600 2024-10-24
Mt6000 Firmware HIGH 7.5
CVE-2024-28077

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, a…

Mitigation only
Fix from $1,950 2024-08-26
Mt6000 Firmware MEDIUM 5.3
CVE-2024-39229

An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.…

No fix yet
Fix from $1,600 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39227

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39225EPSS 15%

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39226EPSS 21%

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39228

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Mt6000 Firmware HIGH 7.5
CVE-2024-27356EPSS 24%

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user infor…

Mitigation only
Fix from $1,950 2024-02-27
Gl Ax1800 Firmware CRITICAL 9.8
CVE-2023-50919EPSS 48%

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affect…

No fix yet
Fix from $2,300 2024-01-12
Gl Ax1800 Firmware MEDIUM 5.5
CVE-2023-50920

An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share …

No fix yet
Fix from $1,600 2024-01-12
Gl Mt1300 Firmware CRITICAL 9.8
CVE-2023-50921

An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. T…

Mitigation only
Fix from $2,300 2024-01-03
Gl Mt1300 Firmware HIGH 7.2
CVE-2023-50922

An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploadi…

No fix yet
Fix from $1,950 2024-01-03
Gl Mt1300 Firmware HIGH 7.8
CVE-2023-50445EPSS 9%

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N…

No fix yet
Fix from $1,950 2023-12-28
Gl Ar300m Firmware CRITICAL 9.8
CVE-2023-46454EPSS 23%

In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package in…

Mitigation only
Fix from $2,300 2023-12-12
Gl Ar300m Firmware CRITICAL 9.8
CVE-2023-46456EPSS 25%

In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionali…

Mitigation only
Fix from $2,300 2023-12-12
Gl Ar300m Firmware HIGH 7.5
CVE-2023-46455EPSS 47%

In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file …

Mitigation only
Fix from $1,950 2023-12-12