Gl Mt3000
Vendor:
First CVE: May 2, 2023 · Active for 3 years
18
Total CVEs
More Total CVEs than 93% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gl Mt3000 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2023
3 years ago
Most Recent CVE
Oct 24, 2024
640 days ago
CVE Severity & Scoring
Gl Mt300018 CVEs
17%
56%
28%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (11.1%)
Network11 (61.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (27.8%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (22.2%)
High2 (11.1%)
None12 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50919CRITICAL An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AX | Jan 12, 2024 | 9.8 | 66 | NO | YES |
CVE-2023-31478HIGH An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. | May 9, 2023 | 7.5 | 50 | NO | YES |
CVE-2023-29778CRITICAL GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | May 2, 2023 | 9.8 | 39 | NO | NO |
CVE-2023-50445HIGH Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR75 | Dec 28, 2023 | 7.8 | 36 | NO | YES |
CVE-2023-31475CRITICAL An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the | May 11, 2023 | 9.8 | 36 | NO | NO |
CVE-2023-31472HIGH An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a comm | May 9, 2023 | 7.5 | 33 | NO | NO |
CVE-2023-31471CRITICAL An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because t | May 10, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-50921CRITICAL An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 | Jan 3, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-31477HIGH A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, becau | May 11, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31474HIGH An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obta | May 9, 2023 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
11.1% of CVEs· 97th percentile
Nuclei
1 CVE
5.6% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Gl Mt3000
Top CWEs
Versions
No cataloged versions.