do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T07:26:01.085Z
Reserved: 2022-05-27T00:00:00
Link: CVE-2022-31793
No data.
Status : Modified
Published: 2022-08-04T22:15:08.017
Modified: 2024-11-21T07:05:20.330
Link: CVE-2022-31793
No data.
OpenCVE Enrichment
No data.
Weaknesses