ZeroHour

Vulnerabilities

57 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32292
+3 in the same advisory: …32291 …32290 …32293
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.

NVD description · AI analysis pending
9.3
group max
<1%
  • gl-inet comet gl-rm1 firmware
CVE-2026-26792
+4 in the same advisory: …26795 …26791 …26793 …26794
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version,

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow attackers to execute arbitrary commands via a crafted input.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • gl-inet ar300m16 firmware
CVE-2025-67091
+1 in the same advisory: …67090
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable.

An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory.

NVD description · AI analysis pending
6.5
group max
3% PoC ×2
  • gl-inet ax1800 firmware
CVE-2025-67089
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8.

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

NVD description · AI analysis pending
8.12% PoC
  • gl-inet gl-axt1800 firmware
CVE-2024-45263
+1 in the same advisory: …45260
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2.

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.

NVD description · AI analysis pending
8.8
group max
<1%
  • gl-inet mt6000 firmware
  • gl-inet mt3000 firmware
  • gl-inet mt2500 firmware
  • +1 more
CVE-2024-45262
+1 in the same advisory: …45261
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2.

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • gl-inet mt2500 firmware
  • gl-inet axt1800 firmware
  • gl-inet ax1800 firmware
  • +1 more
CVE-2024-45259
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2.

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.

NVD description · AI analysis pending
6.5<1% PoC
  • gl-inet mt3000 firmware
  • gl-inet mt2500 firmware
  • gl-inet axt1800 firmware
  • +1 more
CVE-2024-28077
A denial-of-service issue was discovered on certain GL-iNet devices.

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special characters (such as half parentheses or square brackets), one can call the login interface and cause the session-management program to crash, resulting in customers being unable to log into their devices. This affects MT6000 4.5.6, XE3000 4.4.5, X3000 4.4.6, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-V2 4.3.10, and XE300 4.3.16.

NVD description · AI analysis pending
7.5<1%
  • gl-inet mt6000 firmware
  • gl-inet x3000 firmware
  • gl-inet xe3000 firmware
  • +1 more
CVE-2024-39226
+4 in the same advisory: …39225 …39227 …39228 …39229
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to manipulate routers by passing malicious shell commands through the s2s API.

NVD description · AI analysis pending
9.8
group max
20% PoC
  • gl-inet mt6000 firmware
  • gl-inet a1300 firmware
  • gl-inet x300b firmware
  • +1 more
CVE-2024-27356
An issue was discovered on certain GL-iNet devices.

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.

NVD description · AI analysis pending
7.524%
  • gl-inet mt6000 firmware
  • gl-inet xe3000 firmware
  • gl-inet x3000 firmware
  • +1 more
CVE-2023-50919
+1 in the same advisory: …50920
An issue was discovered on GL.iNet devices before version 4.5.0.

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.

NVD description · AI analysis pending
9.8
group max
48% PoC
  • gl-inet gl-ax1800 firmware
  • gl-inet gl-axt1800 firmware
  • gl-inet gl-mt3000 firmware
  • +1 more
CVE-2023-50921
+1 in the same advisory: …50922
An issue was discovered on GL.iNet devices through 4.5.0.

An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.

NVD description · AI analysis pending
9.8
group max
<1%
  • gl-inet gl-mt1300 firmware
  • gl-inet gl-mt300n-v2 firmware
  • gl-inet gl-ar750s firmware
  • +1 more
CVE-2023-50445
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7,

Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the get_system_log and get_crash_log functions of the logread module, as well as the upgrade_online function of the upgrade module.

NVD description · AI analysis pending
7.89% PoC
  • gl-inet gl-mt1300 firmware
  • gl-inet gl-mt300n-v2 firmware
  • gl-inet gl-ar750s firmware
  • +1 more
CVE-2023-46456
+2 in the same advisory: …46454 …46455
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

NVD description · AI analysis pending
9.8
group max
25%
  • gl-inet gl-ar300m firmware
CVE-2023-47463
+1 in the same advisory: …47464
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the g

Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.

NVD description · AI analysis pending
9.8
group max
1%
  • gl-inet gl-ax1800 firmware
CVE-2023-47462
Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function.

Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function.

NVD description · AI analysis pending
9.81% PoC
  • gl-inet gl-ax1800 firmware
CVE-2023-24261
A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.

A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.

NVD description · AI analysis pending
7.219% PoC
  • gl-inet gl-e750 firmware
CVE-2023-33621
+1 in the same advisory: …33620
GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded.

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

NVD description · AI analysis pending
5.9<1% PoC
  • gl-inet gl-ar750s firmware
CVE-2023-31475
+2 in the same advisory: …31477 …31473
An issue was discovered on GL.iNet devices before 3.216.

An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.

NVD description · AI analysis pending
9.8
group max
14% PoC
  • gl-inet gl-s20 firmware
  • gl-inet gl-x3000 firmware
  • gl-inet gl-mt3000 firmware
  • +1 more
CVE-2023-31471
An issue was discovered on GL.iNet devices before 3.216.

An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.

NVD description · AI analysis pending
9.81% PoC
  • gl-inet gl-s20 firmware
  • gl-inet gl-x3000 firmware
  • gl-inet gl-mt3000 firmware
  • +1 more
CVE-2023-31478
+2 in the same advisory: …31472 …31474
An issue was discovered on GL.iNet devices before 3.216.

An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.

NVD description · AI analysis pending
7.530% PoC
  • gl-inet gl-s20 firmware
  • gl-inet gl-x3000 firmware
  • gl-inet gl-mt3000 firmware
  • +1 more
CVE-2023-31476
An issue was discovered on GL.iNet devices running firmware before 3.216.

An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).

NVD description · AI analysis pending
7.5<1% PoC
  • gl-inet gl-mv1000w firmware
  • gl-inet gl-mv1000 firmware
CVE-2023-29778
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

NVD description · AI analysis pending
9.816% PoC
  • gl-inet gl-mt3000 firmware
CVE-2022-44211
+1 in the same advisory: …44212
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.

In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.

NVD description · AI analysis pending
7.4
group max
<1%
  • gl-inet goodcloud
CVE-2022-42055
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow atta

Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.

NVD description · AI analysis pending
6.52% PoC
  • gl-inet goodcloud