Description
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Subscriptions
Arris
Subscribe
Bgw210
Subscribe
Bgw210 Firmware
Subscribe
Bgw320
Subscribe
Bgw320 Firmware
Subscribe
Nvg443
Subscribe
Nvg443 Firmware
Subscribe
Nvg510
Subscribe
Nvg510 Firmware
Subscribe
Nvg589
Subscribe
Nvg589 Firmware
Subscribe
Nvg599
Subscribe
Nvg599 Firmware
Subscribe
Inglorion
Subscribe
Muhttpd
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T07:26:01.085Z
Reserved: 2022-05-27T00:00:00.000Z
Link: CVE-2022-31793
No data.
Status : Modified
Published: 2022-08-04T22:15:08.017
Modified: 2024-11-21T07:05:20.330
Link: CVE-2022-31793
No data.
OpenCVE Enrichment
No data.
Weaknesses