Vulnerability CVE-2023-46454


Published: 2023-12-12   Modified: 2023-12-14

Description:
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

 References:
https://cyberaz0r.info/2023/11/glinet-multiple-vulnerabilities/

Copyright 2026, cxsecurity.com

 

Back to Top