GL.iNet manufactures a modestly represented line of compact WiFi routers and portable networking devices intended for travel and remote deployment, including models such as the GL-MT3000, AR300M16, and GL-AX1800. The vendor's vulnerability disclosures span firmware and hardware configuration issues distributed across this focused product portfolio. Defenders tracking this vendor should focus on inventory and firmware management practices for affected devices; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gl Inet over time
Signals from CVEs in this vendor scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50919CRITICAL An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AX | Jan 12, 2024 | 9.8 | 66 | NO | YES |
CVE-2023-46455HIGH In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality. | Dec 12, 2023 | 7.5 | 58 | NO | YES |
CVE-2023-31478HIGH An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. | May 9, 2023 | 7.5 | 50 | NO | YES |
CVE-2024-27356HIGH An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5 | Feb 27, 2024 | 7.5 | 44 | NO | YES |
CVE-2019-6275HIGH Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. | Mar 21, 2019 | 8.8 | 44 | NO | YES |
CVE-2019-6272HIGH Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. | Mar 21, 2019 | 8.8 | 43 | NO | YES |
CVE-2023-46456CRITICAL In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality. | Dec 12, 2023 | 9.8 | 42 | NO | NO |
CVE-2019-6274HIGH Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal seq | Mar 21, 2019 | 8.8 | 42 | NO | YES |
CVE-2023-46454CRITICAL In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality. | Dec 12, 2023 | 9.8 | 40 | NO | NO |
CVE-2023-29778CRITICAL GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | May 2, 2023 | 9.8 | 39 | NO | NO |
Signals from CVEs in this vendor scope (57 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gl Inet.
Media articles that mention a CVE ID that affects a product developed by Gl Inet — matched by CVE ID, not by vendor name.