First published: Wed Jan 03 2024(Updated: )
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
GL.iNet GL-MT1300 Firmware | =4.3.7 | |
GL.iNet GL-MT1300 | ||
All of | ||
GL.iNet GL-MT300N-V2 Firmware | =4.3.7 | |
gl-inet gl-mt300n-v2 firmware | ||
All of | ||
GL.iNet GL-AR750 Firmware | =4.3.7 | |
GL.iNet GL-AR750 Firmware | ||
All of | ||
GL.iNet GL-AR750 Firmware | =4.3.7 | |
GL.iNet GL-AR750 Firmware | ||
All of | ||
GL.iNet GL-AR300M Firmware | =4.3.7 | |
GL.iNet GL-AR300M Firmware | ||
All of | ||
GL.iNet GL-B1300 Firmware | =4.3.7 | |
GL.iNet GL-B1300 Firmware | ||
All of | ||
GL.iNet GL-MT6000 | =4.5.0 | |
GL.iNet GL-MT6000 | ||
All of | ||
GL.iNet GL-A1300 Firmware | =4.4.6 | |
GL.iNet GL-A1300 Firmware | ||
All of | ||
Netgear Nighthawk AX1800 Firmware | =4.4.6 | |
GL.iNet GL-AX1800 | ||
All of | ||
gl-inet gl-axt1800 | =4.4.6 | |
GL.iNet GL-AX1800 | ||
All of | ||
GL.iNet GL-MT3000 Firmware | =4.4.6 | |
GL.iNet GL-MT3000 | ||
All of | ||
GL.iNet GL-MT2500 | =4.4.6 | |
GL.iNet GL-MT2500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50921 has a high severity due to the potential for attackers to gain root privileges on affected GL.iNet devices.
To fix CVE-2023-50921, upgrade your GL.iNet device firmware to the latest available version that addresses this vulnerability.
CVE-2023-50921 affects several GL.iNet devices, including A1300, AX1800, AXT1800, MT3000, MT2500, and MT6000 among others.
Yes, CVE-2023-50921 can be exploited remotely if the attacker has access to the add_user interface on the vulnerable devices.
The impact of CVE-2023-50921 is significant as it allows unauthorized users to gain root access, potentially compromising device integrity and security.