4.9
CVE-2023-31473
- EPSS 2.47%
- Veröffentlicht 11.05.2023 11:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gl-inet ≫ Gl-s20 Firmware Version < 3.216
Gl-inet ≫ Gl-x3000 Firmware Version < 3.216
Gl-inet ≫ Gl-mt3000 Firmware Version < 3.216
Gl-inet ≫ Gl-mt2500 Firmware Version < 3.216
Gl-inet ≫ Gl-mt2500a Firmware Version < 3.216
Gl-inet ≫ Gl-axt1800 Firmware Version < 3.216
Gl-inet ≫ Gl-a1300 Firmware Version < 3.216
Gl-inet ≫ Gl-ax1800 Firmware Version < 3.216
Gl-inet ≫ Gl-sft1200 Firmware Version < 3.216
Gl-inet ≫ Gl-mt1300 Firmware Version < 3.216
Gl-inet ≫ Gl-e750 Firmware Version < 3.216
Gl-inet ≫ Gl-mv1000 Firmware Version < 3.216
Gl-inet ≫ Gl-mv1000w Firmware Version < 3.216
Gl-inet ≫ Gl-s10 Firmware Version < 3.216
Gl-inet ≫ Gl-s200 Firmware Version < 3.216
Gl-inet ≫ Gl-s1300 Firmware Version < 3.216
Gl-inet ≫ Gl-sf1200 Firmware Version < 3.216
Gl-inet ≫ Gl-b1300 Firmware Version < 3.216
Gl-inet ≫ Gl-b2200 Firmware Version < 3.216
Gl-inet ≫ Gl-ap1300 Firmware Version < 3.216
Gl-inet ≫ Gl-ap1300lte Firmware Version < 3.216
Gl-inet ≫ Gl-x1200 Firmware Version < 3.216
Gl-inet ≫ Gl-x750 Firmware Version < 3.216
Gl-inet ≫ Gl-x300b Firmware Version < 3.216
Gl-inet ≫ Gl-xe300 Firmware Version < 3.216
Gl-inet ≫ Gl-ar750s Firmware Version < 3.216
Gl-inet ≫ Gl-ar750 Firmware Version < 3.216
Gl-inet ≫ Gl-mifi Firmware Version < 3.216
Gl-inet ≫ Gl-mt300n-v2 Firmware Version < 3.216
Gl-inet ≫ Gl-ar300m Firmware Version < 3.216
Gl-inet ≫ Gl-usb150 Firmware Version < 3.216
Gl-inet ≫ Microuter-n300 Firmware Version < 3.216
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.47% | 0.85 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.