CVE-2023-31473
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.
- Affected products
- Gl.Inet
- Gl-inet gl-s20 Firmware
- < 3.216
- Fix
- Available
- CVSS 3.1
- 4.9 MEDIUM
- EPSS
- 3.9% (89th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2023-05-11
CVE-2023-31473 at NVD
No indexed exploits for CVE-2023-31473 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-31473 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.