CRITICAL🇵🇱 Wersja polska

CVE-2023-47463

CVSS 9.8v3.1pub. 2023-11-30upd. 2024-11-21

Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.

🤖 AI Analysis
How it works

The vulnerability consists of improper permission verification in the gl_nas_sys authentication function. An attacker can send a specially crafted script to this function over the network without needing to possess any credentials. The function does not properly enforce required permissions, allowing a malicious payload to be passed and executed directly on the device.

Impact

An attacker gains the ability to execute arbitrary code on the vulnerable device (RCE), which may lead to complete takeover of the router, violation of data confidentiality and integrity, and disruption of its operation.

Mitigation & patch

GL.iNet AX1800 firmware should be updated to version 4.5.0 or newer. Patches and details are available in the manufacturer's references on GitHub.

Who is affected

GL.iNet AX1800 with firmware version 4.0.0 to below 4.5.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Gl Inet Gl Ax1800

    HW
    Gl-Inet
    all versions
  • Gl Inet Gl Ax1800 Firmware

    OS
    Gl-Inet
    4.0.0 – 4.5.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-50919CRITICAL9.8PL ✓same product

GL.iNet — Authentication Bypass w NGINX przez dopasowanie wzorców Lua

CVE-2023-50921CRITICAL9.8PL ✓same product

GL.iNet: privilege escalation przez interfejs add_user do uprawnień root

CVE-2023-47462CRITICAL9.8PL ✓same product

Nieprawidłowe uprawnienia w GL.iNet AX1800 umożliwiające zdalne wykonanie kodu

CVE-2023-31475CRITICAL9.8PL ✓same product

Buffer overflow w GL.iNet libglutil.so — zdalne wykonanie kodu

CVE-2023-31471CRITICAL9.8PL ✓same product

GL.iNet — instalacja dowolnego oprogramowania przez obejście weryfikacji po stronie klienta