Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-46454: cyberaz0r Security Blog | GL.iNet Multiple Vulnerabilities

In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

CVE
#vulnerability#git

CVE-2023-46454: Remote Command Execution

Affected Products and Versions: GL.iNet GL-AR300M routers with firmware v4.3.7
CVSSv3.1 Score: 7.2 (High)
CVSSv3.1 Attack Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Discoverer: Michele ‘cyberaz0r’ Di Bonaventura
Exploit: GitHub

Executive Summary

In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

Update GL.iNet GL-AR300M router firmware to the latest version.

Reference

https://nvd.nist.gov/vuln/detail/CVE-2023-46454

CVE-2023-46455: Arbitrary File Write

Affected Products and Versions: GL.iNet GL-AR300M routers with firmware v4.3.7
CVSSv3.1 Score: 7.2 (High)
CVSSv3.1 Attack Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Discoverer: Michele ‘cyberaz0r’ Di Bonaventura
Exploit: GitHub

Executive Summary

In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.

Update GL.iNet GL-AR300M router firmware to the latest version.

Reference

https://nvd.nist.gov/vuln/detail/CVE-2023-46455

CVE-2023-46456: Remote Command Execution

Affected Products and Versions: GL.iNet GL-AR300M routers with firmware v3.216
CVSSv3.1 Score: 7.2 (High)
CVSSv3.1 Attack Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Discoverer: Michele ‘cyberaz0r’ Di Bonaventura
Exploit: GitHub

Executive Summary

In GL.iNET GL-AR300M routers with firmware v3.216, it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

Update GL.iNet GL-AR300M router firmware to the latest version.

Reference

https://nvd.nist.gov/vuln/detail/CVE-2023-46456

Related news

GL.iNet AR300M 3.216 Remote Code Execution

GL.iNet AR300M versions 3.216 and below suffer from an OpenVPN client related remote code execution vulnerability.

GL.iNet AR300M 4.3.7 Remote Code Execution

GL.iNet AR300M versions 4.3.7 and below suffer from an OpenVPN client related remote code execution vulnerability.

GL.iNet AR300M 4.3.7 Arbitrary File Write

GL.iNet AR300M versions 4.3.7 and below suffer from an arbitrary file writing vulnerability.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907