CVE-2023-31473

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gl-inet:gl-s20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s20:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:gl-inet:gl-x3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x3000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt3000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt2500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt2500a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:gl-inet:gl-axt1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-axt1800:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:gl-inet:gl-a1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-a1300:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:gl-inet:gl-ax1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ax1800:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:gl-inet:gl-sft1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sft1200:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt1300:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:gl-inet:gl-e750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-e750:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:gl-inet:gl-mv1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:gl-inet:gl-mv1000w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000w:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:gl-inet:gl-s10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s10:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:gl-inet:gl-s200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s200:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:gl-inet:gl-s1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s1300:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:gl-inet:gl-sf1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sf1200:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:gl-inet:gl-b1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b1300:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:gl-inet:gl-b2200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b2200:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:gl-inet:gl-ap1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:gl-inet:gl-ap1300lte_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300lte:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:gl-inet:gl-x1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x1200:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:gl-inet:gl-x750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x750:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:gl-inet:gl-x300b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x300b:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:gl-inet:gl-xe300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-xe300:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:gl-inet:gl-ar750s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750s:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:gl-inet:gl-ar750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:gl-inet:gl-mifi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mifi:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt300n-v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt300n-v2:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:gl-inet:gl-ar300m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar300m:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:gl-inet:gl-usb150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-usb150:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:gl-inet:microuter-n300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:microuter-n300:-:*:*:*:*:*:*:*

History

22 May 2023, 18:25

Type Values Removed Values Added
References (MISC) https://www.gl-inet.com - (MISC) https://www.gl-inet.com - Vendor Advisory
References (MISC) https://github.com/gl-inet/CVE-issues/blob/main/3.215/Arbitrary_File_Read.md - (MISC) https://github.com/gl-inet/CVE-issues/blob/main/3.215/Arbitrary_File_Read.md - Exploit, Third Party Advisory
CWE CWE-77
First Time Gl-inet gl-e750
Gl-inet gl-x300b
Gl-inet gl-xe300
Gl-inet gl-s20
Gl-inet gl-x750 Firmware
Gl-inet gl-ap1300
Gl-inet gl-usb150 Firmware
Gl-inet gl-ax1800
Gl-inet gl-sft1200 Firmware
Gl-inet gl-mt300n-v2
Gl-inet gl-s10
Gl-inet gl-sft1200
Gl-inet gl-b2200 Firmware
Gl-inet gl-x750
Gl-inet gl-ap1300lte Firmware
Gl-inet gl-mt1300 Firmware
Gl-inet gl-ax1800 Firmware
Gl-inet gl-x300b Firmware
Gl-inet gl-ap1300lte
Gl-inet gl-e750 Firmware
Gl-inet gl-mt1300
Gl-inet gl-s200 Firmware
Gl-inet microuter-n300
Gl-inet gl-usb150
Gl-inet gl-a1300 Firmware
Gl-inet gl-x3000 Firmware
Gl-inet gl-ar750 Firmware
Gl-inet gl-ar750s
Gl-inet gl-mt2500 Firmware
Gl-inet gl-ap1300 Firmware
Gl-inet gl-mv1000w
Gl-inet gl-mv1000w Firmware
Gl-inet gl-xe300 Firmware
Gl-inet gl-mt2500a
Gl-inet gl-mt2500
Gl-inet gl-axt1800
Gl-inet gl-b1300 Firmware
Gl-inet gl-s1300
Gl-inet gl-x1200
Gl-inet gl-mifi Firmware
Gl-inet gl-b2200
Gl-inet gl-s200
Gl-inet
Gl-inet gl-mv1000
Gl-inet gl-a1300
Gl-inet gl-sf1200
Gl-inet gl-mifi
Gl-inet gl-x3000
Gl-inet gl-x1200 Firmware
Gl-inet gl-mt3000 Firmware
Gl-inet gl-mt2500a Firmware
Gl-inet gl-ar300m Firmware
Gl-inet gl-b1300
Gl-inet gl-mv1000 Firmware
Gl-inet gl-s1300 Firmware
Gl-inet gl-ar750
Gl-inet gl-ar300m
Gl-inet gl-mt3000
Gl-inet microuter-n300 Firmware
Gl-inet gl-mt300n-v2 Firmware
Gl-inet gl-axt1800 Firmware
Gl-inet gl-sf1200 Firmware
Gl-inet gl-ar750s Firmware
Gl-inet gl-s20 Firmware
Gl-inet gl-s10 Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
CPE cpe:2.3:h:gl-inet:gl-s10:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-sft1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mv1000w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-axt1800:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-xe300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ap1300lte_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750s:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:microuter-n300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x1200:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b1300:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ax1800:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt3000:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt2500a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-e750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-e750:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-usb150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ap1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-sf1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b2200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ar750s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mifi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:microuter-n300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt300n-v2:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ar750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mifi:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sft1200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-axt1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s20:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x300b:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-usb150:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar300m:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300lte:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mv1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-a1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sf1200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-b1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-b2200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x750:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt300n-v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500a:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ax1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x3000:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s1300:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt1300:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-xe300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt2500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x300b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ar300m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000w:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-a1300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s1300_firmware:*:*:*:*:*:*:*:*

11 May 2023, 13:36

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-11 11:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-31473

Mitre link : CVE-2023-31473

CVE.ORG link : CVE-2023-31473


JSON object : View

Products Affected

gl-inet

  • gl-xe300_firmware
  • gl-x1200
  • gl-mt300n-v2
  • gl-ar750
  • gl-mt1300
  • gl-sft1200
  • gl-s10_firmware
  • gl-s1300
  • gl-ap1300lte
  • gl-xe300
  • gl-a1300
  • gl-sf1200_firmware
  • gl-mt2500_firmware
  • gl-ax1800_firmware
  • gl-ar750s_firmware
  • gl-mv1000w_firmware
  • gl-s1300_firmware
  • gl-b2200_firmware
  • gl-s20_firmware
  • microuter-n300
  • gl-mifi
  • gl-b1300
  • gl-s200_firmware
  • gl-ap1300lte_firmware
  • gl-mt2500a
  • gl-mt3000_firmware
  • gl-s10
  • gl-b1300_firmware
  • gl-e750
  • gl-ar300m
  • gl-b2200
  • gl-sft1200_firmware
  • gl-s200
  • gl-usb150_firmware
  • gl-mt3000
  • gl-x300b_firmware
  • gl-ap1300
  • gl-x3000
  • gl-sf1200
  • gl-mv1000
  • gl-mv1000_firmware
  • gl-x300b
  • gl-ar750s
  • microuter-n300_firmware
  • gl-mt2500
  • gl-a1300_firmware
  • gl-mifi_firmware
  • gl-ar300m_firmware
  • gl-x3000_firmware
  • gl-mt1300_firmware
  • gl-e750_firmware
  • gl-s20
  • gl-ap1300_firmware
  • gl-mt2500a_firmware
  • gl-ax1800
  • gl-mt300n-v2_firmware
  • gl-usb150
  • gl-x1200_firmware
  • gl-x750
  • gl-x750_firmware
  • gl-mv1000w
  • gl-axt1800
  • gl-ar750_firmware
  • gl-axt1800_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')