CVE-2023-31471

CRITICALCVSS 9.8/10EPSS 1.05%

Last modified

CVE-2023-31471 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. EPSS estimates a 1.05% chance of exploitation in the next 30 days.

Description

An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.05%

60.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Gl-InetGl-S20 Firmware< 3.216
Gl-InetGl-X3000 Firmware< 3.216
Gl-InetGl-Mt3000 Firmware< 3.216
Gl-InetGl-Mt2500 Firmware< 3.216
Gl-InetGl-Mt2500a Firmware< 3.216
Gl-InetGl-Axt1800 Firmware< 3.216
Gl-InetGl-A1300 Firmware< 3.216
Gl-InetGl-Ax1800 Firmware< 3.216
Gl-InetGl-Sft1200 Firmware< 3.216
Gl-InetGl-Mt1300 Firmware< 3.216
Gl-InetGl-E750 Firmware< 3.216
Gl-InetGl-Mv1000 Firmware< 3.216
Gl-InetGl-Mv1000w Firmware< 3.216
Gl-InetGl-S10 Firmware< 3.216
Gl-InetGl-S200 Firmware< 3.216
Gl-InetGl-S1300 Firmware< 3.216
Gl-InetGl-Sf1200 Firmware< 3.216
Gl-InetGl-B1300 Firmware< 3.216
Gl-InetGl-B2200 Firmware< 3.216
Gl-InetGl-Ap1300 Firmware< 3.216
Gl-InetGl-Ap1300lte Firmware< 3.216
Gl-InetGl-X1200 Firmware< 3.216
Gl-InetGl-X750 Firmware< 3.216
Gl-InetGl-X300b Firmware< 3.216
Gl-InetGl-Xe300 Firmware< 3.216
Gl-InetGl-Ar750s Firmware< 3.216
Gl-InetGl-Ar750 Firmware< 3.216
Gl-InetGl-Mifi Firmware< 3.216
Gl-InetGl-Mt300n-V2 Firmware< 3.216
Gl-InetGl-Ar300m Firmware< 3.216
Gl-InetGl-Usb150 Firmware< 3.216
Gl-InetMicrouter-N300 Firmware< 3.216

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-31471?
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.
How severe is CVE-2023-31471?
CVE-2023-31471 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.05% probability of exploitation in the next 30 days.
How do I fix CVE-2023-31471?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-31471?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST