CVE-2023-50922: Malicious File Upload
An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a crontab-formatted file to a specific directory and waiting for its execution. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50922?
CVE-2023-50922 has a high severity rating due to the potential for arbitrary code execution on vulnerable GL.iNet devices.
How do I fix CVE-2023-50922?
To fix CVE-2023-50922, update your GL.iNet device firmware to a version that is not affected by this vulnerability.
Which GL.iNet devices are impacted by CVE-2023-50922?
CVE-2023-50922 affects various GL.iNet devices including A1300, AX1800, AXT1800, MT3000, and firmware versions up to 4.5.0.
What type of attack can exploit CVE-2023-50922?
CVE-2023-50922 can be exploited by attackers who steal the AdminToken cookie to execute arbitrary code.
Is there a known workaround for CVE-2023-50922?
There are no specific workarounds mentioned for CVE-2023-50922, updating the firmware is the recommended action.