PT-2023-23350 · Gl.Inet · Gl.Inet

CVE-2023-31471

·

Publicado

2023-05-10

·

Atualizado

2025-01-27

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GL.iNet devices versions prior to 3.216
Description An issue was discovered that allows the installation of arbitrary software, such as a reverse shell, through the software installation feature. This is possible because the restrictions on the available package list are limited to client-side verification, allowing software installation from the filesystem, the package list, or a URL.
Recommendations For versions prior to 3.216, as a temporary workaround, consider disabling the software installation feature until a patch is available. Restrict access to the software installation module to minimize the risk of exploitation. Avoid using the software installation feature to install software from untrusted sources, such as arbitrary URLs or unverified packages, until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-31471

Produtos afetados

Gl.Inet