CVE-2023-50919

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
gl-inetgl-ax1800_firmware
4.3.7
gl-inetgl-ax1800_firmware
4.4.6
gl-inetgl-axt1800_firmware
4.3.7
gl-inetgl-axt1800_firmware
4.4.6
gl-inetgl-mt3000_firmware
4.3.7
gl-inetgl-mt3000_firmware
4.4.6
gl-inetgl-mt2500_firmware
4.3.7
gl-inetgl-mt2500_firmware
4.4.6
gl-inetgl-mt6000_firmware
4.3.7
gl-inetgl-mt6000_firmware
4.4.6
gl-inetgl-mt1300_firmware
4.3.7
gl-inetgl-mt1300_firmware
4.4.6
gl-inetgl-mt300n-v2_firmware
4.3.7
gl-inetgl-mt300n-v2_firmware
4.4.6
gl-inetgl-ar750s_firmware
4.3.7
gl-inetgl-ar750s_firmware
4.4.6
gl-inetgl-ar750_firmware
4.3.7
gl-inetgl-ar750_firmware
4.4.6
gl-inetgl-ar300m_firmware
4.3.7
gl-inetgl-ar300m_firmware
4.4.6
gl-inetgl-b1300_firmware
4.3.7
gl-inetgl-b1300_firmware
4.4.6
gl-inetgl-a1300_firmware
4.3.7
gl-inetgl-a1300_firmware
4.4.6
𝑥
= Vulnerable software versions