First published: Tue May 09 2023(Updated: )
An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
gl-inet gl-mv1000 firmware | <=3.215 | |
GL.iNet GL-MV1000W | ||
All of | ||
GL.iNet GL-MV1000 Firmware | <=3.215 | |
GL.iNet GL-MV1000 | ||
gl-inet gl-mv1000 firmware | <=3.215 | |
GL.iNet GL-MV1000W | ||
GL.iNet GL-MV1000 Firmware | <=3.215 | |
GL.iNet GL-MV1000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31476 is an arbitrary file write vulnerability on GL.iNet devices running firmware before 3.216.
CVE-2023-31476 allows an attacker to create an empty file with a filename and path of up to 6 characters almost anywhere on the filesystem, as long as the working directory is /www.
GL-MV1000W Firmware versions up to 3.215 and GL-MV1000 Firmware versions up to 3.215 are affected by CVE-2023-31476.
CVE-2023-31476 has a severity level of 7.5 (High).
To fix CVE-2023-31476, update your GL.iNet device firmware to version 3.216 or later.