CVE-2023-50922

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jan 3, 2024
Updated: Jan 10, 2024
CWE ID 434

Summary

CVE-2023-50922: A serious vulnerability was discovered in various GL.iNet devices, including A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7. This issue allows attackers to execute arbitrary code by stealing the AdminToken cookie and uploading a crontab-formatted file to a specific directory, which will then be executed automatically. Thus, unauthorized users can gain administrative control over affected devices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share