CVE-2023-31476: Command Injection
An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31476?
CVE-2023-31476 is an arbitrary file write vulnerability on GL.iNet devices running firmware before 3.216.
How does CVE-2023-31476 work?
CVE-2023-31476 allows an attacker to create an empty file with a filename and path of up to 6 characters almost anywhere on the filesystem, as long as the working directory is /www.
Which GL.iNet devices are affected by CVE-2023-31476?
GL-MV1000W Firmware versions up to 3.215 and GL-MV1000 Firmware versions up to 3.215 are affected by CVE-2023-31476.
What is the severity of CVE-2023-31476?
CVE-2023-31476 has a severity level of 7.5 (High).
How can I fix CVE-2023-31476?
To fix CVE-2023-31476, update your GL.iNet device firmware to version 3.216 or later.