Записи GL-iNet
57 опубликованных записей вендора gl-inet.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 3,5 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-307 Improper Restriction of Excessive Authentication Attempts4
- CWE-284 Improper Access Control2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
57 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2023-50919Готовый эксплойт | An issue was discovered on GL.iNet devices before version 4.5.0.gl-inet · gl-ax1800 firmware · CWE-287 | Критическая9,8 | — | 47,8 % | 12 янв. 2024 г. |
46В плане | CVE-2023-46456Эксплойта нет | In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload fugl-inet · gl-ar300m firmware · CWE-74 | Критическая9,8 | — | 24,7 % | 12 дек. 2023 г. |
46В плане | CVE-2023-46454Proof of concept | In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the pgl-inet · gl-ar300m firmware · CWE-78 | Критическая9,8 | — | 23,5 % | 12 дек. 2023 г. |
45В плане | CVE-2024-39226Эксплойта нет | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,gl-inet · mt6000 firmware · CWE-22 | Критическая9,8 | — | 20,4 % | 6 авг. 2024 г. |
44В плане | CVE-2023-46455Proof of concept | In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN cligl-inet · gl-ar300m firmware · CWE-22 | Высокая7,5 | — | 47,0 % | 12 дек. 2023 г. |
44В плане | CVE-2023-29778Эксплойта нет | GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.gl-inet · gl-mt3000 firmware · CWE-78 | Критическая9,8 | — | 16,0 % | 2 мая 2023 г. |
43В плане | CVE-2024-39225Эксплойта нет | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,gl-inet · mt6000 firmware · CWE-307 | Критическая9,8 | — | 14,4 % | 6 авг. 2024 г. |
43В плане | CVE-2023-31475Эксплойта нет | An issue was discovered on GL.iNet devices before 3.216.gl-inet · gl-s20 firmware · CWE-120 | Критическая9,8 | — | 13,7 % | 11 мая 2023 г. |
42В плане | CVE-2023-47464Proof of concept | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the ugl-inet · gl-ax1800 firmware · CWE-22 | Высокая8,8 | — | 22,6 % | 30 нояб. 2023 г. |
40В плане | CVE-2026-26792Эксплойта нет | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_ugl-inet · ar300m16 firmware · CWE-77 | Критическая9,8 | — | 4,0 % | 12 мар. 2026 г. |
40В плане | CVE-2026-26793Эксплойта нет | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function.gl-inet · ar300m16 firmware · CWE-77 | Критическая9,8 | — | 3,6 % | 12 мар. 2026 г. |
40В плане | CVE-2026-26795Эксплойта нет | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log fungl-inet · ar300m16 firmware · CWE-77 | Критическая9,8 | — | 3,6 % | 12 мар. 2026 г. |
40В плане | CVE-2026-26791Эксплойта нет | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_sergl-inet · ar300m16 firmware · CWE-77 | Критическая9,8 | — | 3,6 % | 12 мар. 2026 г. |
39Наблюдать | CVE-2023-31478Proof of concept | An issue was discovered on GL.iNet devices before 3.216.gl-inet · gl-s20 firmware | Высокая7,5 | — | 29,7 % | 9 мая 2023 г. |
39Наблюдать | CVE-2019-6272Proof of concept | Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitragl-inet · gl-ar300m-lite firmware · CWE-77 | Высокая8,8 | — | 12,5 % | 21 мар. 2019 г. |
39Наблюдать | CVE-2019-6275Proof of concept | Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbigl-inet · gl-ar300m-lite firmware · CWE-77 | Высокая8,8 | — | 12,5 % | 21 мар. 2019 г. |
39Наблюдать | CVE-2023-47462Эксплойта нет | Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file shargl-inet · gl-ax1800 firmware · CWE-276 | Критическая9,8 | — | 1,3 % | 29 нояб. 2023 г. |
39Наблюдать | CVE-2023-47463Эксплойта нет | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cragl-inet · gl-ax1800 firmware · CWE-281 | Критическая9,8 | — | 1,3 % | 30 нояб. 2023 г. |
39Наблюдать | CVE-2024-39227Эксплойта нет | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,gl-inet · mt6000 firmware · CWE-74 | Критическая9,8 | — | 1,2 % | 6 авг. 2024 г. |
39Наблюдать | CVE-2023-31471Эксплойта нет | An issue was discovered on GL.iNet devices before 3.216.gl-inet · gl-s20 firmware | Критическая9,8 | — | 1,1 % | 10 мая 2023 г. |
39Наблюдать | CVE-2024-39228Эксплойта нет | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,gl-inet · mt6000 firmware · CWE-78 | Критическая9,8 | — | 0,7 % | 6 авг. 2024 г. |
39Наблюдать | CVE-2023-50921Эксплойта нет | An issue was discovered on GL.iNet devices through 4.5.0.gl-inet · gl-mt1300 firmware · CWE-269 | Критическая9,8 | — | 0,5 % | 3 янв. 2024 г. |
38Наблюдать | CVE-2019-6274Proof of concept | Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecgl-inet · gl-ar300m-lite firmware · CWE-22 | Высокая8,8 | — | 11,2 % | 21 мар. 2019 г. |
37Наблюдать | CVE-2024-27356Proof of concept | An issue was discovered on certain GL-iNet devices.gl-inet · mt6000 firmware · CWE-200 | Высокая7,5 | — | 23,9 % | 26 февр. 2024 г. |
37Наблюдать | CVE-2026-32292Эксплойта нет | GL-iNet Comet (GL-RM1) KVM insufficient login rate-limitinggl-inet · comet gl-rm1 firmware · CWE-307 | Критическая9,3 | — | 0,6 % | 17 мар. 2026 г. |
- CVE-2023-5091953В плане
An issue was discovered on GL.iNet devices before version 4.5.0.
КритическаяCVSS 9,8Готовый эксплойтEPSS 48 %gl-inet · gl-ax1800 firmware12 янв. 2024 г.
- CVE-2023-4645646В плане
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload fu
КритическаяCVSS 9,8Эксплойта нетEPSS 25 %gl-inet · gl-ar300m firmware12 дек. 2023 г.
- CVE-2023-4645446В плане
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the p
КритическаяCVSS 9,8Proof of conceptEPSS 23 %gl-inet · gl-ar300m firmware12 дек. 2023 г.
- CVE-2024-3922645В плане
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %gl-inet · mt6000 firmware6 авг. 2024 г.
- CVE-2023-4645544В плане
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN cli
ВысокаяCVSS 7,5Proof of conceptEPSS 47 %gl-inet · gl-ar300m firmware12 дек. 2023 г.
- CVE-2023-2977844В плане
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
КритическаяCVSS 9,8Эксплойта нетEPSS 16 %gl-inet · gl-mt3000 firmware2 мая 2023 г.
- CVE-2024-3922543В плане
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %gl-inet · mt6000 firmware6 авг. 2024 г.
- CVE-2023-3147543В плане
An issue was discovered on GL.iNet devices before 3.216.
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %gl-inet · gl-s20 firmware11 мая 2023 г.
- CVE-2023-4746442В плане
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the u
ВысокаяCVSS 8,8Proof of conceptEPSS 23 %gl-inet · gl-ax1800 firmware30 нояб. 2023 г.
- CVE-2026-2679240В плане
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_u
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %gl-inet · ar300m16 firmware12 мар. 2026 г.
- CVE-2026-2679340В плане
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %gl-inet · ar300m16 firmware12 мар. 2026 г.
- CVE-2026-2679540В плане
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log fun
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %gl-inet · ar300m16 firmware12 мар. 2026 г.
- CVE-2026-2679140В плане
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_ser
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %gl-inet · ar300m16 firmware12 мар. 2026 г.
- CVE-2023-3147839Наблюдать
An issue was discovered on GL.iNet devices before 3.216.
ВысокаяCVSS 7,5Proof of conceptEPSS 30 %gl-inet · gl-s20 firmware9 мая 2023 г.
- CVE-2019-627239Наблюдать
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitra
ВысокаяCVSS 8,8Proof of conceptEPSS 13 %gl-inet · gl-ar300m-lite firmware21 мар. 2019 г.
- CVE-2019-627539Наблюдать
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbi
ВысокаяCVSS 8,8Proof of conceptEPSS 13 %gl-inet · gl-ar300m-lite firmware21 мар. 2019 г.
- CVE-2023-4746239Наблюдать
Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file shar
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gl-inet · gl-ax1800 firmware29 нояб. 2023 г.
- CVE-2023-4746339Наблюдать
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cra
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gl-inet · gl-ax1800 firmware30 нояб. 2023 г.
- CVE-2024-3922739Наблюдать
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gl-inet · mt6000 firmware6 авг. 2024 г.
- CVE-2023-3147139Наблюдать
An issue was discovered on GL.iNet devices before 3.216.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gl-inet · gl-s20 firmware10 мая 2023 г.
- CVE-2024-3922839Наблюдать
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gl-inet · mt6000 firmware6 авг. 2024 г.
- CVE-2023-5092139Наблюдать
An issue was discovered on GL.iNet devices through 4.5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gl-inet · gl-mt1300 firmware3 янв. 2024 г.
- CVE-2019-627438Наблюдать
Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspec
ВысокаяCVSS 8,8Proof of conceptEPSS 11 %gl-inet · gl-ar300m-lite firmware21 мар. 2019 г.
- CVE-2024-2735637Наблюдать
An issue was discovered on certain GL-iNet devices.
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %gl-inet · mt6000 firmware26 февр. 2024 г.
- CVE-2026-3229237Наблюдать
GL-iNet Comet (GL-RM1) KVM insufficient login rate-limiting
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %gl-inet · comet gl-rm1 firmware17 мар. 2026 г.