CVE-2023-31471
Gl-Inet Gl-S20 Firmware ≤ 3.216
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2023-31471 is a critical-severity an unspecified weakness vulnerability in Gl-Inet Gl-S20 Firmware. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 39% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-35776
Vulnerability Data
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It…
more
is possible to install software from the filesystem, the package list, or a URL.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.