CVE-2023-50920: Medium severity gl-inet Gl-ax1800 Firmware vulnerability
An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authentication or access control measures. Attackers can impersonate legitimate users or perform unauthorized actions. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50920?
CVE-2023-50920 is considered a high severity vulnerability due to the risk of unauthorized access by attackers.
How do I fix CVE-2023-50920?
To fix CVE-2023-50920, upgrade your GL.iNet device firmware to version 4.5.0 or later.
Which devices are affected by CVE-2023-50920?
CVE-2023-50920 affects GL.iNet devices running firmware versions prior to 4.5.0.
What type of vulnerability is CVE-2023-50920?
CVE-2023-50920 is an authentication bypass vulnerability allowing attackers to impersonate legitimate users.
Can attackers exploit CVE-2023-50920 remotely?
Yes, attackers can exploit CVE-2023-50920 remotely by sharing session identifiers between different user sessions.