NA

CVE-2023-31473

Published: 11/05/2023 Updated: 22/05/2023
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

An issue exists on GL.iNet devices prior to 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gl-inet gl-s20_firmware

gl-inet gl-x3000_firmware

gl-inet gl-mt3000_firmware

gl-inet gl-mt2500_firmware

gl-inet gl-mt2500a_firmware

gl-inet gl-axt1800_firmware

gl-inet gl-a1300_firmware

gl-inet gl-ax1800_firmware

gl-inet gl-sft1200_firmware

gl-inet gl-mt1300_firmware

gl-inet gl-e750_firmware

gl-inet gl-mv1000_firmware

gl-inet gl-mv1000w_firmware

gl-inet gl-s10_firmware

gl-inet gl-s200_firmware

gl-inet gl-s1300_firmware

gl-inet gl-sf1200_firmware

gl-inet gl-b1300_firmware

gl-inet gl-b2200_firmware

gl-inet gl-ap1300_firmware

gl-inet gl-ap1300lte_firmware

gl-inet gl-x1200_firmware

gl-inet gl-x750_firmware

gl-inet gl-x300b_firmware

gl-inet gl-xe300_firmware

gl-inet gl-ar750s_firmware

gl-inet gl-ar750_firmware

gl-inet gl-mifi_firmware

gl-inet gl-mt300n-v2_firmware

gl-inet gl-ar300m_firmware

gl-inet gl-usb150_firmware

gl-inet microuter-n300_firmware