CVE-2023-31478

An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.
References
Link Resource
https://github.com/gl-inet/CVE-issues/blob/main/3.215/SSID_Key_Disclosure.md Exploit Issue Tracking Third Party Advisory
https://www.gl-inet.com Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gl-inet:gl-s20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s20:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:gl-inet:gl-x3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x3000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt3000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt2500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt2500a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:gl-inet:gl-axt1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-axt1800:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:gl-inet:gl-a1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-a1300:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:gl-inet:gl-ax1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ax1800:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:gl-inet:gl-sft1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sft1200:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt1300:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:gl-inet:gl-e750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-e750:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:gl-inet:gl-mv1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:gl-inet:gl-mv1000w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000w:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:gl-inet:gl-s10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s10:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:gl-inet:gl-s200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s200:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:gl-inet:gl-s1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s1300:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:gl-inet:gl-sf1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sf1200:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:gl-inet:gl-b1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b1300:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:gl-inet:gl-b2200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b2200:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:gl-inet:gl-ap1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:gl-inet:gl-ap1300lte_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300lte:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:gl-inet:gl-x1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x1200:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:gl-inet:gl-x750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x750:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:gl-inet:gl-x300b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x300b:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:gl-inet:gl-xe300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-xe300:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:gl-inet:gl-ar750s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750s:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:gl-inet:gl-ar750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:gl-inet:gl-mifi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mifi:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:gl-inet:gl-mt300n-v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt300n-v2:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:gl-inet:gl-ar300m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar300m:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:gl-inet:gl-usb150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-usb150:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:gl-inet:microuter-n300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:microuter-n300:-:*:*:*:*:*:*:*

History

17 May 2023, 16:04

Type Values Removed Values Added
CPE cpe:2.3:h:gl-inet:gl-s10:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-sft1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mv1000w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-axt1800:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-xe300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ap1300lte_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750s:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:microuter-n300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x1200:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b1300:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar750:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ax1800:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt3000:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt2500a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-e750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-e750:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-usb150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ap1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-sf1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-b2200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ar750s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mifi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:microuter-n300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt300n-v2:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ar750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mifi:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sft1200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-axt1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s20:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x300b:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-usb150:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ar300m:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-ap1300lte:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mv1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-a1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-sf1200:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-b1300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-b2200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x750:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt300n-v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt2500a:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ax1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-x3000:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-s1300:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mt1300:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-xe300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt2500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x300b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ar300m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-mv1000w:-:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-a1300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-s1300_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE NVD-CWE-noinfo
References (MISC) https://www.gl-inet.com - (MISC) https://www.gl-inet.com - Product
References (MISC) https://github.com/gl-inet/CVE-issues/blob/main/3.215/SSID_Key_Disclosure.md - (MISC) https://github.com/gl-inet/CVE-issues/blob/main/3.215/SSID_Key_Disclosure.md - Exploit, Issue Tracking, Third Party Advisory
First Time Gl-inet gl-e750
Gl-inet gl-x300b
Gl-inet gl-xe300
Gl-inet gl-s20
Gl-inet gl-x750 Firmware
Gl-inet gl-ap1300
Gl-inet gl-usb150 Firmware
Gl-inet gl-ax1800
Gl-inet gl-sft1200 Firmware
Gl-inet gl-mt300n-v2
Gl-inet gl-s10
Gl-inet gl-sft1200
Gl-inet gl-b2200 Firmware
Gl-inet gl-x750
Gl-inet gl-ap1300lte Firmware
Gl-inet gl-mt1300 Firmware
Gl-inet gl-ax1800 Firmware
Gl-inet gl-x300b Firmware
Gl-inet gl-ap1300lte
Gl-inet gl-e750 Firmware
Gl-inet gl-mt1300
Gl-inet gl-s200 Firmware
Gl-inet microuter-n300
Gl-inet gl-usb150
Gl-inet gl-a1300 Firmware
Gl-inet gl-x3000 Firmware
Gl-inet gl-ar750 Firmware
Gl-inet gl-ar750s
Gl-inet gl-mt2500 Firmware
Gl-inet gl-ap1300 Firmware
Gl-inet gl-mv1000w
Gl-inet gl-mv1000w Firmware
Gl-inet gl-xe300 Firmware
Gl-inet gl-mt2500a
Gl-inet gl-mt2500
Gl-inet gl-axt1800
Gl-inet gl-b1300 Firmware
Gl-inet gl-s1300
Gl-inet gl-x1200
Gl-inet gl-mifi Firmware
Gl-inet gl-b2200
Gl-inet gl-s200
Gl-inet
Gl-inet gl-mv1000
Gl-inet gl-a1300
Gl-inet gl-sf1200
Gl-inet gl-mifi
Gl-inet gl-x3000
Gl-inet gl-x1200 Firmware
Gl-inet gl-mt3000 Firmware
Gl-inet gl-mt2500a Firmware
Gl-inet gl-ar300m Firmware
Gl-inet gl-b1300
Gl-inet gl-mv1000 Firmware
Gl-inet gl-s1300 Firmware
Gl-inet gl-ar750
Gl-inet gl-ar300m
Gl-inet gl-mt3000
Gl-inet microuter-n300 Firmware
Gl-inet gl-mt300n-v2 Firmware
Gl-inet gl-axt1800 Firmware
Gl-inet gl-sf1200 Firmware
Gl-inet gl-ar750s Firmware
Gl-inet gl-s20 Firmware
Gl-inet gl-s10 Firmware

09 May 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-09 23:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-31478

Mitre link : CVE-2023-31478

CVE.ORG link : CVE-2023-31478


JSON object : View

Products Affected

gl-inet

  • gl-mv1000w_firmware
  • gl-b1300_firmware
  • gl-ap1300lte
  • gl-ar750s
  • gl-mt1300_firmware
  • gl-s20
  • gl-mt2500
  • gl-sf1200_firmware
  • gl-x1200_firmware
  • gl-ar750s_firmware
  • gl-ap1300_firmware
  • gl-mifi_firmware
  • gl-usb150_firmware
  • microuter-n300
  • gl-axt1800
  • gl-e750_firmware
  • gl-ax1800
  • gl-s1300_firmware
  • gl-mt300n-v2
  • gl-a1300
  • gl-xe300_firmware
  • gl-b1300
  • gl-b2200
  • gl-s10_firmware
  • gl-ax1800_firmware
  • gl-xe300
  • gl-mv1000
  • gl-ar750_firmware
  • gl-s10
  • gl-mv1000w
  • gl-mt3000_firmware
  • gl-a1300_firmware
  • gl-x300b
  • gl-s1300
  • gl-mt1300
  • gl-mv1000_firmware
  • gl-mt3000
  • gl-x750_firmware
  • gl-ar300m_firmware
  • gl-x1200
  • gl-s200
  • gl-x3000
  • gl-ap1300lte_firmware
  • microuter-n300_firmware
  • gl-x3000_firmware
  • gl-ap1300
  • gl-mt2500_firmware
  • gl-x750
  • gl-usb150
  • gl-mt2500a
  • gl-sf1200
  • gl-x300b_firmware
  • gl-ar300m
  • gl-e750
  • gl-sft1200
  • gl-b2200_firmware
  • gl-ar750
  • gl-s200_firmware
  • gl-mt300n-v2_firmware
  • gl-axt1800_firmware
  • gl-mifi
  • gl-mt2500a_firmware
  • gl-s20_firmware
  • gl-sft1200_firmware