Arbitrary Software Installation Vulnerability in GL.iNet Devices
CVE-2023-31471
9.8CRITICAL
What is CVE-2023-31471?
An arbitrary software installation vulnerability exists in GL.iNet devices prior to version 3.216, allowing attackers to install unauthorized software. This exploitation arises from insufficient verification of the package list, enabling the installation of malicious software, such as reverse shells, from the filesystem, a URL, or through the package list. This critical security flaw underscores the need for enhanced restrictions and server-side verification processes.
