Gl-inet
Gl-inet Gl-s200 Firmware: vulnerabilidades y CVE
Gl-inet Gl-s200 Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-31475 | Crítica (9.8) | 14% | — | 11 may 2023 | An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to… |
| CVE-2023-31473 | Media (4.9) | 3.9% | — | 11 may 2023 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a… |
| CVE-2023-31477 | Alta (7.5) | 0.94% | — | 11 may 2023 | A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction… |
| CVE-2023-31471 | Crítica (9.8) | 1.1% | — | 10 may 2023 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available… |
| CVE-2023-31478 | Alta (7.5) | 30% | — | 9 may 2023 | An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. |
| CVE-2023-31474 | Alta (7.5) | 0.82% | — | 9 may 2023 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific… |
| CVE-2023-31472 | Alta (7.5) | 20% | — | 9 may 2023 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a… |