An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Gl-inet
Subscribe
|
Gl-a1300
Subscribe
Gl-a1300 Firmware
Subscribe
Gl-ar300m
Subscribe
Gl-ar300m Firmware
Subscribe
Gl-ar750
Subscribe
Gl-ar750 Firmware
Subscribe
Gl-ar750s
Subscribe
Gl-ar750s Firmware
Subscribe
Gl-ax1800
Subscribe
Gl-ax1800 Firmware
Subscribe
Gl-axt1800
Subscribe
Gl-axt1800 Firmware
Subscribe
Gl-b1300
Subscribe
Gl-b1300 Firmware
Subscribe
Gl-mt1300
Subscribe
Gl-mt1300 Firmware
Subscribe
Gl-mt2500
Subscribe
Gl-mt2500 Firmware
Subscribe
Gl-mt3000
Subscribe
Gl-mt3000 Firmware
Subscribe
Gl-mt300n-v2
Subscribe
Gl-mt300n-v2 Firmware
Subscribe
Gl-mt6000
Subscribe
Gl-mt6000 Firmware
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 03 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-03T14:06:33.752Z
Reserved: 2023-12-15T00:00:00.000Z
Link: CVE-2023-50919
Updated: 2024-08-02T22:23:44.046Z
Status : Modified
Published: 2024-01-12T08:15:43.533
Modified: 2025-06-03T14:15:34.507
Link: CVE-2023-50919
No data.
OpenCVE Enrichment
No data.
Weaknesses