CVE-2023-33620: Medium severity gl-inet Gl-ar750s Firmware vulnerability
Published Jun 13, 2023
·Updated
GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle attack.
Affected Software
4 affected components
All of the following
gl-inet Gl-ar750s Firmware=3.215
gl-inet Gl-ar750s
gl-inet Gl-ar750s Firmware=3.215
gl-inet Gl-ar750s
Event History
Jun 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of GL.iNET GL-AR750S-Ext firmware v3.215?
The vulnerability ID is CVE-2023-33620.
2
What is the severity of CVE-2023-33620?
The severity of CVE-2023-33620 is medium (5.9).
3
What is the affected software version of CVE-2023-33620?
The affected software version is GL.iNET GL-AR750S-Ext firmware v3.215.
4
How can attackers exploit CVE-2023-33620?
Attackers can exploit CVE-2023-33620 by eavesdropping via a man-in-the-middle attack.
5
Are there any references for CVE-2023-33620?
Yes, the following references are available: http://gl-ar750s-ext.com, http://glinet.com, https://justinapplegate.me/2023/glinet-CVE-2023-33620/