PT-2023-24407 · Gl.Inet · Gl-Ar750S-Ext

Published

2023-06-13

·

Updated

2023-06-23

·

CVE-2023-33620

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GL.iNET GL-AR750S-Ext version 3.215
Description The issue allows attackers to eavesdrop via a man-in-the-middle attack due to the use of an insecure protocol in its communications.
Recommendations For GL.iNET GL-AR750S-Ext version 3.215, consider updating to a newer version that addresses the insecure protocol issue. As a temporary workaround, restrict access to sensitive communications to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-33620

Affected Products

Gl-Ar750S-Ext