GL.iNet.Software.Installation.Information.Disclosure
Description
This indicates an attack attempt to exploit an Information Disclosure vulnerability in GL.iNet devices.
The vulnerability is caused by the software installation feature of the device when handling a crafted HTTP POST request. An attacker can exploit this to get access to a list of files in a specific directory in the device's file system.
Affected Products
GL.iNet devices versions prior to 3.216.
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://www.gl-inet.com/
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2023-06-06 | 23.571 |