Gl Inet
gl-inet
57 CVEs • 135 products
Products (135)
Click to collapseToggle
Products (135)
Click to collapse
CVEs (57)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Gl Inet 1Comet Gl Rm1 Firmware Apr 27, 2026 Mar 17, 2026 6.3 MEDIUM· v4 3.7 LOW· v3 N/A· v2 The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to se...Show more |
1Gl Inet 1Comet Gl Rm1 Firmware Apr 27, 2026 Mar 17, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials. |
1Gl Inet 1Comet Gl Rm1 Firmware Apr 27, 2026 Mar 17, 2026 7.0 HIGH· v4 6.8 MEDIUM· v3 N/A· v2 The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins. |
1Gl Inet 1Comet Gl Rm1 Firmware Apr 27, 2026 Mar 17, 2026 7.0 HIGH· v4 4.7 MEDIUM· v3 N/A· v2 The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the cor...Show more |
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. |
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a c...Show more |
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP reques...Show more |
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and...Show more |
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands...Show more |
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root...Show more |
The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authenti...Show more |
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreSep 29, 2025 Oct 24, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the fi...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentia...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete co...Show more |
1Gl Inet 21A1300 Firmware Ar300m16 FirmwareAr300m Firmware+18 moreOct 15, 2025 Oct 24, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on t...Show more |
1Gl Inet 18A1300 Firmware Ar300m16 FirmwareAr300m Firmware+15 moreMar 14, 2025 Aug 26, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are e...Show more |
1Gl Inet 28A1300 Firmware Ap1300 FirmwareAr300m16 Firmware+25 moreNov 21, 2024 Aug 6, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4,...Show more |
1Gl Inet 28A1300 Firmware Ap1300 FirmwareAr300m16 Firmware+25 moreAug 15, 2024 Aug 6, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were d...Show more |