Vulnerabilities and Bug Fix

GL.iNet is announcing a list of fixed vulnerabilities and CVEs on firmwares and cloud products. Please note that this does not include CVEs from OpenWrt.

Please note that some CVE codes may be reserved but details about the vulnerabilities may be kept restricted until the issue has been fixed for a majority of users, the purpose is to prevent exploits using the vulnerabilities.

If you wish to report vulnerabilities or bugs, please send an email to support@glinet.biz , we have a 90-day policy for vulnerability disclosure.


  1. CVE-2022-31898
    • Summary: Command Injection in network tools in router firmware allows changing router settings
    • Affected software: Firmware 3.212 and earlier
    • Credits: Olivier Boschko Laflamme
    • Attention: Users please upgrade firmware to 3.215 and newer

  1. CVE-2022-42054
    • Summary: XSS in company name and description in Goodcloud allows attackers to get user right
    • Affected software: GoodCloud 1.0 and earlier
    • Credits: Olivier Boschko Laflamme

  1. CVE-2022-42055
    • Summary: Command inject from Goodcloud allows attackers to gain control of users’ routers
    • Affected software: Firmware 3.212 and earlier, Goodcloud 1.0 and earlier
    • Credits: Olivier Boschko Laflamme

  1. CVE-2022-44211
    • Summary: Insecure design allows attacker to gain control of user’s devices via device Cloud ID
    • Affected software: GoodCloud 1.0 and earlier
    • Credits: Goutham Rukmasah and Kushal Arvind Shah of Fortinet’s FortiGuard Labs

  1. CVE-2022-44212
    • Summary: Insecure design allows attacker to have remote access of user’s devices via device ID
    • Affected software: GoodCloud 1.0 and earlier
    • Credits: Goutham Rukmasah and Kushal Arvind Shah of Fortinet’s FortiGuard Labs
About GL.iNet

GL.iNet builds network hardware and software solutions that bring affordable and secure network connectivity to families and businesses all over the world. We work with a wide range of industries, solving everyday internet problems in offices, and providing complex networking solutions such as smart buildings and IoT Networks. At GL.iNet, We believe all successful businesses build upon a strong and secure foundation, which is why our highest priority is perfecting network security and reliability for our partners.