Description
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35778 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file. |
References
History
Mon, 27 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Gl-inet
Subscribe
Gl-a1300
Subscribe
Gl-a1300 Firmware
Subscribe
Gl-ap1300
Subscribe
Gl-ap1300 Firmware
Subscribe
Gl-ap1300lte
Subscribe
Gl-ap1300lte Firmware
Subscribe
Gl-ar300m
Subscribe
Gl-ar300m Firmware
Subscribe
Gl-ar750
Subscribe
Gl-ar750 Firmware
Subscribe
Gl-ar750s
Subscribe
Gl-ar750s Firmware
Subscribe
Gl-ax1800
Subscribe
Gl-ax1800 Firmware
Subscribe
Gl-axt1800
Subscribe
Gl-axt1800 Firmware
Subscribe
Gl-b1300
Subscribe
Gl-b1300 Firmware
Subscribe
Gl-b2200
Subscribe
Gl-b2200 Firmware
Subscribe
Gl-e750
Subscribe
Gl-e750 Firmware
Subscribe
Gl-mifi
Subscribe
Gl-mifi Firmware
Subscribe
Gl-mt1300
Subscribe
Gl-mt1300 Firmware
Subscribe
Gl-mt2500
Subscribe
Gl-mt2500 Firmware
Subscribe
Gl-mt2500a
Subscribe
Gl-mt2500a Firmware
Subscribe
Gl-mt3000
Subscribe
Gl-mt3000 Firmware
Subscribe
Gl-mt300n-v2
Subscribe
Gl-mt300n-v2 Firmware
Subscribe
Gl-mv1000
Subscribe
Gl-mv1000 Firmware
Subscribe
Gl-mv1000w
Subscribe
Gl-mv1000w Firmware
Subscribe
Gl-s10
Subscribe
Gl-s10 Firmware
Subscribe
Gl-s1300
Subscribe
Gl-s1300 Firmware
Subscribe
Gl-s20
Subscribe
Gl-s200
Subscribe
Gl-s200 Firmware
Subscribe
Gl-s20 Firmware
Subscribe
Gl-sf1200
Subscribe
Gl-sf1200 Firmware
Subscribe
Gl-sft1200
Subscribe
Gl-sft1200 Firmware
Subscribe
Gl-usb150
Subscribe
Gl-usb150 Firmware
Subscribe
Gl-x1200
Subscribe
Gl-x1200 Firmware
Subscribe
Gl-x3000
Subscribe
Gl-x3000 Firmware
Subscribe
Gl-x300b
Subscribe
Gl-x300b Firmware
Subscribe
Gl-x750
Subscribe
Gl-x750 Firmware
Subscribe
Gl-xe300
Subscribe
Gl-xe300 Firmware
Subscribe
Microuter-n300
Subscribe
Microuter-n300 Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-27T17:18:23.785Z
Reserved: 2023-04-28T00:00:00.000Z
Link: CVE-2023-31473
Updated: 2024-08-02T14:53:30.985Z
Status : Modified
Published: 2023-05-11T11:15:09.100
Modified: 2025-01-27T18:15:33.730
Link: CVE-2023-31473
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD