PT-2023-30032 · Gl.Inet · Gl-Ar300M
Cyberaz0R
+1
·
Publicado
2023-12-07
·
Atualizado
2023-12-14
·
CVE-2023-46454
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GL.iNET GL-AR300M version 4.3.7
Description
The issue allows for the injection of arbitrary shell commands through a crafted package name in the package information functionality. This can potentially lead to unauthorized access and control of the device.
Recommendations
For version 4.3.7, consider restricting access to the package information functionality until a patch is available. As a temporary workaround, avoid using the package information feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gl-Ar300M