NA

CVE-2023-31476

Published: 09/05/2023 Updated: 16/05/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists on GL.iNet devices running firmware prior to 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gl-inet gl-mv1000w_firmware

gl-inet gl-mv1000_firmware