CVE-2023-50919

EUVD-2023-55650
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
gl-inetgl-ax1800_firmware
4.3.7
gl-inetgl-ax1800_firmware
4.4.6
gl-inetgl-axt1800_firmware
4.3.7
gl-inetgl-axt1800_firmware
4.4.6
gl-inetgl-mt3000_firmware
4.3.7
gl-inetgl-mt3000_firmware
4.4.6
gl-inetgl-mt2500_firmware
4.3.7
gl-inetgl-mt2500_firmware
4.4.6
gl-inetgl-mt6000_firmware
4.3.7
gl-inetgl-mt6000_firmware
4.4.6
gl-inetgl-mt1300_firmware
4.3.7
gl-inetgl-mt1300_firmware
4.4.6
gl-inetgl-mt300n-v2_firmware
4.3.7
gl-inetgl-mt300n-v2_firmware
4.4.6
gl-inetgl-ar750s_firmware
4.3.7
gl-inetgl-ar750s_firmware
4.4.6
gl-inetgl-ar750_firmware
4.3.7
gl-inetgl-ar750_firmware
4.4.6
gl-inetgl-ar300m_firmware
4.3.7
gl-inetgl-ar300m_firmware
4.4.6
gl-inetgl-b1300_firmware
4.3.7
gl-inetgl-b1300_firmware
4.4.6
gl-inetgl-a1300_firmware
4.3.7
gl-inetgl-a1300_firmware
4.4.6
𝑥
= Vulnerable software versions