Cyber Resilience

CVE-2023-31471

Gl-Inet Gl-S20 Firmware ≤ 3.216

Public PoC
Published
10 May 2023
Modified
27 January 2025
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.011 61th percentile
Risk Priority 73 floored blend · peak EPSS

Summary

CVE-2023-31471 is a critical-severity an unspecified weakness vulnerability in Gl-Inet Gl-S20 Firmware. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 39% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It…

more

is possible to install software from the filesystem, the package list, or a URL.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-31472Same product: Gl-Inet Gl-A1300
CVE-2023-31474Same product: Gl-Inet Gl-A1300
CVE-2023-31475Same product: Gl-Inet Gl-A1300
CVE-2023-31478Same product: Gl-Inet Gl-A1300
CVE-2023-31477Same product: Gl-Inet Gl-A1300
CVE-2023-31473Same product: Gl-Inet Gl-A1300
CVE-2023-50922Same product: Gl-Inet Gl-A1300
CVE-2023-50921Same product: Gl-Inet Gl-A1300
CVE-2023-50445Same product: Gl-Inet Gl-A1300
CVE-2023-50919Same product: Gl-Inet Gl-A1300

Affected Assets

gl-inet
gl-s20 firmware
≤ 3.216
gl-inet
gl-x3000 firmware
≤ 3.216
gl-inet
gl-mt3000 firmware
≤ 3.216
gl-inet
gl-mt2500 firmware
≤ 3.216
gl-inet
gl-mt2500a firmware
≤ 3.216
gl-inet
gl-axt1800 firmware
≤ 3.216
gl-inet
gl-a1300 firmware
≤ 3.216
gl-inet
gl-ax1800 firmware
≤ 3.216
gl-inet
gl-sft1200 firmware
≤ 3.216
gl-inet
gl-mt1300 firmware
≤ 3.216
+22 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References