First published: Thu May 11 2023(Updated: )
A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GL.iNet GL-S20 Firmware | <3.216 | |
GL.iNet GL-S20 | ||
GL.iNet GL-X3000 Firmware | <3.216 | |
GL.iNet GL-X3000 | ||
GL.iNet GL-MT3000 Firmware | <3.216 | |
GL.iNet GL-MT3000 | ||
GL.iNet GL-MT2500 | <3.216 | |
GL.iNet GL-MT2500 | ||
GL.iNet GL-MT2500A | <3.216 | |
GL.iNet GL-MT2500A Firmware | ||
gl-inet gl-axt1800 | <3.216 | |
GL.iNet GL-AX1800 | ||
GL.iNet GL-A1300 Firmware | <3.216 | |
GL.iNet GL-A1300 Firmware | ||
Netgear Nighthawk AX1800 Firmware | <3.216 | |
GL.iNet GL-AX1800 | ||
GL.iNet SFT1200 firmware | <3.216 | |
GL.iNet GL-SFT1200 | ||
GL.iNet GL-MT1300 Firmware | <3.216 | |
GL.iNet GL-MT1300 | ||
GL.iNet GL-E750 | <3.216 | |
GL.iNet GL-E750 | ||
GL.iNet GL-MV1000 Firmware | <3.216 | |
GL.iNet GL-MV1000 | ||
gl-inet gl-mv1000 firmware | <3.216 | |
GL.iNet GL-MV1000W | ||
GL.iNet GL-S10 Firmware | <3.216 | |
gl-inet gl-s10 firmware | ||
GL.iNet GL-S200 | <3.216 | |
GL.iNet GL-S200 Firmware | ||
GL.iNet GL-S1300 Firmware | <3.216 | |
GL.iNet GL-S1300 | ||
GL.iNet GL-SF1200 | <3.216 | |
GL.iNet GL-SF1200 | ||
GL.iNet GL-B1300 Firmware | <3.216 | |
GL.iNet GL-B1300 Firmware | ||
GL.iNet GL-B2200 Firmware | <3.216 | |
gl-inet gl-b2200 firmware | ||
GL.iNet GL-AP1300LTE Firmware | <3.216 | |
GL.iNet GL-AP1300 Firmware | ||
GL.iNet GL-AP1300LTE Firmware | <3.216 | |
GL.iNet GL-AP1300LTE Firmware | ||
GL.Inet GL-X1200 Firmware | <3.216 | |
GL.iNet GL-X1200 | ||
GL.iNet GL-X750 Firmware | <3.216 | |
gl-inet gl-x750 firmware | ||
GL.iNet GL-X300B Firmware | <3.216 | |
GL.iNet GL-X300B | ||
gl.inet gl-xe300 firmware | <3.216 | |
gl.inet gl-xe300 firmware | ||
GL.iNet GL-AR750 Firmware | <3.216 | |
GL.iNet GL-AR750 Firmware | ||
GL.iNet GL-AR750 Firmware | <3.216 | |
GL.iNet GL-AR750 Firmware | ||
GL.iNet GL-MiFi Firmware | <3.216 | |
GL.iNet GL-MiFi | ||
GL.iNet GL-MT300N-V2 Firmware | <3.216 | |
gl-inet gl-mt300n-v2 firmware | ||
GL.iNet GL-AR300M Firmware | <3.216 | |
GL.iNet GL-AR300M Firmware | ||
GL.iNet GL-USB150 Firmware | <3.216 | |
GL.iNet GL-USB150 Firmware | ||
GL.iNet Microuter N300 | <3.216 | |
GL.iNet Microuter N300 | ||
All of | ||
GL.iNet GL-S20 Firmware | <3.216 | |
GL.iNet GL-S20 | ||
All of | ||
GL.iNet GL-X3000 Firmware | <3.216 | |
GL.iNet GL-X3000 | ||
All of | ||
GL.iNet GL-MT3000 Firmware | <3.216 | |
GL.iNet GL-MT3000 | ||
All of | ||
GL.iNet GL-MT2500 | <3.216 | |
GL.iNet GL-MT2500 | ||
All of | ||
GL.iNet GL-MT2500A | <3.216 | |
GL.iNet GL-MT2500A Firmware | ||
All of | ||
gl-inet gl-axt1800 | <3.216 | |
GL.iNet GL-AX1800 | ||
All of | ||
GL.iNet GL-A1300 Firmware | <3.216 | |
GL.iNet GL-A1300 Firmware | ||
All of | ||
Netgear Nighthawk AX1800 Firmware | <3.216 | |
GL.iNet GL-AX1800 | ||
All of | ||
GL.iNet SFT1200 firmware | <3.216 | |
GL.iNet GL-SFT1200 | ||
All of | ||
GL.iNet GL-MT1300 Firmware | <3.216 | |
GL.iNet GL-MT1300 | ||
All of | ||
GL.iNet GL-E750 | <3.216 | |
GL.iNet GL-E750 | ||
All of | ||
GL.iNet GL-MV1000 Firmware | <3.216 | |
GL.iNet GL-MV1000 | ||
All of | ||
gl-inet gl-mv1000 firmware | <3.216 | |
GL.iNet GL-MV1000W | ||
All of | ||
GL.iNet GL-S10 Firmware | <3.216 | |
gl-inet gl-s10 firmware | ||
All of | ||
GL.iNet GL-S200 | <3.216 | |
GL.iNet GL-S200 Firmware | ||
All of | ||
GL.iNet GL-S1300 Firmware | <3.216 | |
GL.iNet GL-S1300 | ||
All of | ||
GL.iNet GL-SF1200 | <3.216 | |
GL.iNet GL-SF1200 | ||
All of | ||
GL.iNet GL-B1300 Firmware | <3.216 | |
GL.iNet GL-B1300 Firmware | ||
All of | ||
GL.iNet GL-B2200 Firmware | <3.216 | |
gl-inet gl-b2200 firmware | ||
All of | ||
GL.iNet GL-AP1300LTE Firmware | <3.216 | |
GL.iNet GL-AP1300 Firmware | ||
All of | ||
GL.iNet GL-AP1300LTE Firmware | <3.216 | |
GL.iNet GL-AP1300LTE Firmware | ||
All of | ||
GL.Inet GL-X1200 Firmware | <3.216 | |
GL.iNet GL-X1200 | ||
All of | ||
GL.iNet GL-X750 Firmware | <3.216 | |
gl-inet gl-x750 firmware | ||
All of | ||
GL.iNet GL-X300B Firmware | <3.216 | |
GL.iNet GL-X300B | ||
All of | ||
gl.inet gl-xe300 firmware | <3.216 | |
gl.inet gl-xe300 firmware | ||
All of | ||
GL.iNet GL-AR750 Firmware | <3.216 | |
GL.iNet GL-AR750 Firmware | ||
All of | ||
GL.iNet GL-AR750 Firmware | <3.216 | |
GL.iNet GL-AR750 Firmware | ||
All of | ||
GL.iNet GL-MiFi Firmware | <3.216 | |
GL.iNet GL-MiFi | ||
All of | ||
GL.iNet GL-MT300N-V2 Firmware | <3.216 | |
gl-inet gl-mt300n-v2 firmware | ||
All of | ||
GL.iNet GL-AR300M Firmware | <3.216 | |
GL.iNet GL-AR300M Firmware | ||
All of | ||
GL.iNet GL-USB150 Firmware | <3.216 | |
GL.iNet GL-USB150 Firmware | ||
All of | ||
GL.iNet Microuter N300 | <3.216 | |
GL.iNet Microuter N300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31477 is classified as a high severity vulnerability due to the potential for unauthorized access to arbitrary file system locations.
To fix CVE-2023-31477, upgrade your GL.iNet device firmware to version 3.216 or later.
CVE-2023-31477 affects multiple GL.iNet devices with firmware versions prior to 3.216.
CVE-2023-31477 is a path traversal vulnerability that allows unauthorized directory access.
Yes, CVE-2023-31477 can be exploited remotely through the file sharing feature without server-side restrictions.