CVE-2023-50919
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
- Gl-inet gl-ax1800 Firmware
- = 4.3.7, 4.4.6
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 47.8% (99th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2024-01-12
CVE-2023-50919 at NVD
3 known exploits for CVE-2023-50919
Proof-of-concept code and exploit modules indexed by Sploitus