CVE-2023-31475
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.
Affected (32)
Products: Gl Inet: Gl S20 Firmware, Gl X3000 Firmware, Gl Mt3000 Firmware, Gl Mt2500 Firmware, Gl Mt2500a Firmware, Gl Axt1800 Firmware, Gl A1300 Firmware, Gl Ax1800 Firmware, Gl Sft1200 Firmware, Gl Mt1300 Firmware, Gl E750 Firmware, Gl Mv1000 Firmware, Gl Mv1000w Firmware, Gl S10 Firmware, Gl S200 Firmware, Gl S1300 Firmware, Gl Sf1200 Firmware, Gl B1300 Firmware, Gl B2200 Firmware, Gl Ap1300 Firmware, Gl Ap1300lte Firmware, Gl X1200 Firmware, Gl X750 Firmware, Gl X300b Firmware, Gl Xe300 Firmware, Gl Ar750s Firmware, Gl Ar750 Firmware, Gl Mifi Firmware, Gl Mt300n V2 Firmware, Gl Ar300m Firmware, Gl Usb150 Firmware, Microuter N300 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl S20 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl X3000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mt3000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mt2500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mt2500a | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Axt1800 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl A1300 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Ax1800 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Sft1200 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mt1300 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl E750 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mv1000 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mv1000w | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl S10 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl S200 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl S1300 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Sf1200 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl B1300 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl B2200 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Ap1300 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Ap1300lte | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl X1200 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl X750 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl X300b | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Xe300 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Ar750s | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Ar750 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mifi | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Mt300n V2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Ar300m | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Gl Usb150 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.216 |
| Running on/with | Platform Versions |
|---|---|
Gl Inet Microuter N300 | All versions |
References (6)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.