Arbitrary Software Installation Vulnerability in GL.iNet Devices
CVE-2023-31471

9.8CRITICAL

Key Information:

Vendor

Gl-inet

Vendor
CVE Published:
10 May 2023

What is CVE-2023-31471?

An arbitrary software installation vulnerability exists in GL.iNet devices prior to version 3.216, allowing attackers to install unauthorized software. This exploitation arises from insufficient verification of the package list, enabling the installation of malicious software, such as reverse shells, from the filesystem, a URL, or through the package list. This critical security flaw underscores the need for enhanced restrictions and server-side verification processes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.