PT-2023-23351 · Gl.Inet · Gl.Inet

Published

2023-05-09

·

Updated

2023-06-12

·

CVE-2023-31472

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GL.iNet devices versions prior to 3.216
Description An issue was discovered that allows for arbitrary file write, enabling the creation of an empty file anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied.
Recommendations For versions prior to 3.216, update to version 3.216 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive filesystem areas to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-31472

Affected Products

Gl.Inet