← Back

Gl Inet

gl-inet

57 CVEs • 135 products

Products (135)

Click to collapse
Toggle
X750 Firmware
x750_firmware
E750 Firmware
e750_firmware
N300 Firmware
n300_firmware
Goodcloud
goodcloud
S200 Firmware
s200_firmware
X1200 Firmware
x1200_firmware
Gl Ar150
gl-ar150
Gl Mt300n V2
gl-mt300n-v2
Gl Ax1800
gl-ax1800
Gl Mt3000
gl-mt3000
Gl Mv1000w
gl-mv1000w
Gl Mv1000
gl-mv1000
Gl S20
gl-s20
Gl X3000
gl-x3000
Gl Mt2500
gl-mt2500
Gl Mt2500a
gl-mt2500a
Gl Axt1800
gl-axt1800
Gl A1300
gl-a1300
Gl Sft1200
gl-sft1200
Gl Mt1300
gl-mt1300
Gl E750
gl-e750
Gl S10
gl-s10
Gl S200
gl-s200
Gl S1300
gl-s1300
Gl Sf1200
gl-sf1200
Gl B1300
gl-b1300
Gl B2200
gl-b2200
Gl Ap1300
gl-ap1300
Gl Ap1300lte
gl-ap1300lte
Gl X1200
gl-x1200
Gl X750
gl-x750
Gl X300b
gl-x300b
Gl Xe300
gl-xe300
Gl Ar750s
gl-ar750s
Gl Ar750
gl-ar750
Gl Mifi
gl-mifi
Gl Ar300m
gl-ar300m

CVEs (57)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gl Inet
32Gl A1300 Firmware
Gl Ap1300 FirmwareGl Ap1300lte Firmware+29 more
Jun 17, 2026
May 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction t...Show more
A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.Show less
1Gl Inet
32Gl A1300 Firmware
Gl Ap1300 FirmwareGl Ap1300lte Firmware+29 more
Jun 17, 2026
May 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package...Show more
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.Show less
1Gl Inet
32Gl A1300 Firmware
Gl Ap1300 FirmwareGl Ap1300lte Firmware+29 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.
1Gl Inet
32Gl A1300 Firmware
Gl Ap1300 FirmwareGl Ap1300lte Firmware+29 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific directo...Show more
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific directory, by using the regex feature in a package name.Show less
1Gl Inet
32Gl A1300 Firmware
Gl Ap1300 FirmwareGl Ap1300lte Firmware+29 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filte...Show more
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied.Show less
1Gl Inet
2Gl Mv1000 Firmware
Gl Mv1000w Firmware
Jun 17, 2026
May 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no m...Show more
An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).Show less
1Gl Inet
1Gl Mt3000 Firmware
Jul 9, 2026
May 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
1Gl Inet
1Goodcloud
Jun 17, 2026
Dec 1, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
1Gl Inet
1Goodcloud
Jun 17, 2026
Dec 1, 2022
N/A· v4
7.4 HIGH· v3
N/A· v2
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
1Gl Inet
1Goodcloud
Jun 17, 2026
Oct 27, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.
1Gl Inet
1Goodcloud
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected...Show more
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.Show less
1Gl Inet
2Gl Ax1800 Firmware
Gl Mt300n V2 Firmware
Jun 17, 2026
Oct 27, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.
1Gl Inet
1Gl Ar150 Firmware
Jun 17, 2026
Dec 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.
1Gl Inet
1Gl Ar300m Lite Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
1Gl Inet
1Gl Ar300m Lite Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.
1Gl Inet
1Gl Ar300m Lite Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
1Gl Inet
1Gl Ar300m Lite Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.