Gl-inet
Gl-inet Gl-x750 Firmware: vulnerabilities and CVEs
Gl-inet Gl-x750 Firmware has 7 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31475 | Critical (9.8) | 14% | — | May 11, 2023 | An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to… |
| CVE-2023-31473 | Medium (4.9) | 3.9% | — | May 11, 2023 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a… |
| CVE-2023-31477 | High (7.5) | 0.94% | — | May 11, 2023 | A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction… |
| CVE-2023-31471 | Critical (9.8) | 1.1% | — | May 10, 2023 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available… |
| CVE-2023-31478 | High (7.5) | 30% | — | May 9, 2023 | An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. |
| CVE-2023-31474 | High (7.5) | 0.82% | — | May 9, 2023 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific… |
| CVE-2023-31472 | High (7.5) | 20% | — | May 9, 2023 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a… |