CVE-2023-31471: Critical severity gl-inet Gl-s20 Firmware vulnerability
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31471?
CVE-2023-31471 is classified as a critical vulnerability due to its ability to allow the installation of arbitrary software on GL.iNet devices.
How do I fix CVE-2023-31471?
To fix CVE-2023-31471, update your GL.iNet device firmware to version 3.216 or later, which patches the vulnerability.
Which devices are affected by CVE-2023-31471?
CVE-2023-31471 affects various GL.iNet devices running firmware versions prior to 3.216.
What kind of attack can CVE-2023-31471 enable?
CVE-2023-31471 can enable an attacker to install malicious software, such as a reverse shell, leading to potential remote code execution.
How does CVE-2023-31471 exploit device vulnerabilities?
CVE-2023-31471 exploits the limitations on the package list, which rely solely on client-side verification, allowing unauthorized software installations.