CVE-2023-50919: Critical severity gl-inet Gl-ax1800 Firmware vulnerability
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50919?
CVE-2023-50919 is classified as a high-severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2023-50919?
To mitigate CVE-2023-50919, upgrade your GL.iNet devices to firmware version 4.5.0 or later.
What devices are affected by CVE-2023-50919?
CVE-2023-50919 affects GL.iNet devices running versions before 4.5.0, including A1300, AX1800, and MT3000 among others.
How does CVE-2023-50919 exploit NGINX authentication?
CVE-2023-50919 exploits NGINX authentication through Lua string pattern matching, allowing bypass of access controls.
Is there a workaround for CVE-2023-50919 before upgrading?
While upgrading is recommended, there are no reliable workarounds available for CVE-2023-50919.