GL.iNet.Software.Installation.Information.Disclosure

description-logoDescription

This indicates an attack attempt to exploit an Information Disclosure vulnerability in GL.iNet devices.
The vulnerability is caused by the software installation feature of the device when handling a crafted HTTP POST request. An attacker can exploit this to get access to a list of files in a specific directory in the device's file system.

affected-products-logoAffected Products

GL.iNet devices versions prior to 3.216.

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://www.gl-inet.com/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-06-06 23.571