Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gl Inet

First CVE: Mar 21, 2019Active for: 7 yearsTotal CVEs: 105

GL.iNet manufactures a modestly represented line of compact WiFi routers and portable networking devices intended for travel and remote deployment, including models such as the GL-MT3000, AR300M16, and GL-AX1800. The vendor's vulnerability disclosures span firmware and hardware configuration issues distributed across this focused product portfolio. Defenders tracking this vendor should focus on inventory and firmware management practices for affected devices; live severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
57
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gl Inet over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2019
7 years ago
Most Recent CVE
Mar 17, 2026
129 days ago

Products(135 total)

Top CVEs

Signals from CVEs in this vendor scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-50919CRITICAL
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AX
Jan 12, 20249.866NOYES
CVE-2023-46455HIGH
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
Dec 12, 20237.558NOYES
CVE-2023-31478HIGH
An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.
May 9, 20237.550NOYES
CVE-2024-27356HIGH
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5
Feb 27, 20247.544NOYES
CVE-2019-6275HIGH
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
Mar 21, 20198.844NOYES
CVE-2019-6272HIGH
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
Mar 21, 20198.843NOYES
CVE-2023-46456CRITICAL
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
Dec 12, 20239.842NONO
CVE-2019-6274HIGH
Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal seq
Mar 21, 20198.842NOYES
CVE-2023-46454CRITICAL
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.
Dec 12, 20239.840NONO
CVE-2023-29778CRITICAL
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
May 2, 20239.839NONO
View all 57 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products57 CVEs
28%
40%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (7.0%)
Network45 (78.9%)
Unknown0 (0.0%)
Physical1 (1.8%)
Adjacent Network7 (12.3%)
Attack Complexity
Low50 (87.7%)
High7 (12.3%)
Unknown0 (0.0%)
User Interaction
None54 (94.7%)
Unknown0 (0.0%)
Required3 (5.3%)
Privileges Required
Low14 (24.6%)
High4 (7.0%)
None39 (68.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.5% of CVEs· 98th percentile
Nuclei
2 CVEs
3.5% of CVEs· 95th percentile
ExploitDB
5 CVEs
8.8% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gl Inet.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gl Inet — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gl Inet's Products

View all 2 CNAs →

Top CWEs