PT-2024-14009 · Gl.Inet · Gl.Inet

Published

2024-01-03

·

Updated

2024-01-10

·

CVE-2023-50921

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GL.iNet devices versions 4.3.7 through 4.5.0
Description An issue was discovered on GL.iNet devices, allowing attackers to invoke the add user interface in the system module to gain root privileges. This issue affects various GL.iNet device models.
Recommendations For versions 4.3.7 through 4.5.0, consider disabling the add user interface in the system module as a temporary workaround until a patch is available. Restrict access to the system module to minimize the risk of exploitation. Avoid using the add user interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-50921

Affected Products

Gl.Inet