CVE-2023-50919 describes a critical NGINX authentication bypass vulnerability affecting numerous GL.iNet router models running firmware versions prior to 4.5.0. This flaw, stemming from improper Lua string pattern matching, allows unauthenticated attackers to bypass security controls. With a CVSS score of 9.8 (Critical), it presents a high risk of complete compromise (confidentiality, integrity, availability) due to its network-based attack vector and low attack complexity. While not yet observed in active exploitation (KEV), a Metasploit module exists, indicating readily available exploit code, though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3.7CPE matchmatch criteria | cpe:2.3:o:gl-inet:gl-ax1800_firmware:4.3.7:*:*:*:*:*:*:* | ||
4.4.6CPE matchmatch criteria | cpe:2.3:o:gl-inet:gl-ax1800_firmware:4.4.6:*:*:*:*:*:*:* | ||
4.3.7CPE matchmatch criteria | cpe:2.3:o:gl-inet:gl-axt1800_firmware:4.3.7:*:*:*:*:*:*:* | ||
4.4.6CPE matchmatch criteria | cpe:2.3:o:gl-inet:gl-axt1800_firmware:4.4.6:*:*:*:*:*:*:* | ||
4.3.7CPE matchmatch criteria | cpe:2.3:o:gl-inet:gl-mt3000_firmware:4.3.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.