Ar300m16
Vendor:
First CVE: Feb 27, 2024 · Active for 2 years
17
Total CVEs
More Total CVEs than 93% of tracked products
8.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
8.7
Avg CVSS
Higher Avg CVSS than 78% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ar300m16 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 27, 2024
2 years ago
Most Recent CVE
Mar 12, 2026
137 days ago
CVE Severity & Scoring
Ar300m1617 CVEs
12%
41%
47%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (70.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (29.4%)
Attack Complexity
Low16 (94.1%)
High1 (5.9%)
Unknown0 (0.0%)
User Interaction
None17 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (23.5%)
High0 (0.0%)
None13 (76.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27356HIGH An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5 | Feb 27, 2024 | 7.5 | 44 | NO | YES |
CVE-2024-39226CRITICAL GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S13 | Aug 6, 2024 | 9.8 | 37 | NO | NO |
CVE-2024-39225CRITICAL GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S13 | Aug 6, 2024 | 9.8 | 35 | NO | NO |
CVE-2026-26793CRITICAL GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary comman | Mar 12, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-26795CRITICAL GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attacke | Mar 12, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-26791CRITICAL GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows | Mar 12, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-26792CRITICAL GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, fir | Mar 12, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-26794HIGH GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL datab | Mar 12, 2026 | 8.8 | 29 | NO | NO |
CVE-2024-39227CRITICAL GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S13 | Aug 6, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-39228CRITICAL GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S13 | Aug 6, 2024 | 9.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Ar300m16
Top CWEs
Versions
No cataloged versions.