CVE-2023-31473
Last modified
CVE-2023-31473 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. EPSS estimates a 3.87% chance of exploitation in the next 30 days.
Description
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gl-Inet | Gl-S20 Firmware | < 3.216 |
| Gl-Inet | Gl-X3000 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt3000 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt2500 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt2500a Firmware | < 3.216 |
| Gl-Inet | Gl-Axt1800 Firmware | < 3.216 |
| Gl-Inet | Gl-A1300 Firmware | < 3.216 |
| Gl-Inet | Gl-Ax1800 Firmware | < 3.216 |
| Gl-Inet | Gl-Sft1200 Firmware | < 3.216 |
| Gl-Inet | Gl-Mt1300 Firmware | < 3.216 |
| Gl-Inet | Gl-E750 Firmware | < 3.216 |
| Gl-Inet | Gl-Mv1000 Firmware | < 3.216 |
| Gl-Inet | Gl-Mv1000w Firmware | < 3.216 |
| Gl-Inet | Gl-S10 Firmware | < 3.216 |
| Gl-Inet | Gl-S200 Firmware | < 3.216 |
| Gl-Inet | Gl-S1300 Firmware | < 3.216 |
| Gl-Inet | Gl-Sf1200 Firmware | < 3.216 |
| Gl-Inet | Gl-B1300 Firmware | < 3.216 |
| Gl-Inet | Gl-B2200 Firmware | < 3.216 |
| Gl-Inet | Gl-Ap1300 Firmware | < 3.216 |
| Gl-Inet | Gl-Ap1300lte Firmware | < 3.216 |
| Gl-Inet | Gl-X1200 Firmware | < 3.216 |
| Gl-Inet | Gl-X750 Firmware | < 3.216 |
| Gl-Inet | Gl-X300b Firmware | < 3.216 |
| Gl-Inet | Gl-Xe300 Firmware | < 3.216 |
| Gl-Inet | Gl-Ar750s Firmware | < 3.216 |
| Gl-Inet | Gl-Ar750 Firmware | < 3.216 |
| Gl-Inet | Gl-Mifi Firmware | < 3.216 |
| Gl-Inet | Gl-Mt300n-V2 Firmware | < 3.216 |
| Gl-Inet | Gl-Ar300m Firmware | < 3.216 |
| Gl-Inet | Gl-Usb150 Firmware | < 3.216 |
| Gl-Inet | Microuter-N300 Firmware | < 3.216 |
References
- https://github.com/gl-inet/CVE-issues/blob/main/3.215/Arbitrary_File_Read.mdExploit, Third Party Advisory
- https://www.gl-inet.comVendor Advisory
- https://github.com/gl-inet/CVE-issues/blob/main/3.215/Arbitrary_File_Read.mdExploit, Third Party Advisory
- https://www.gl-inet.comVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-31473?
How severe is CVE-2023-31473?
How do I fix CVE-2023-31473?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-31468An issue was discovered in Inosoft VisiWin 7 through 2022-2.…7.8
- CVE-2023-31469 A REST interface in Apache StreamPipes (versions 0.69.0 to …8.8
- CVE-2023-3147A vulnerability has been found in SourceCodester Online Disc…8.8
- CVE-2023-31470SmartDNS through 41 before 56d0332 allows an out-of-bounds w…9.8
- CVE-2023-31471An issue was discovered on GL.iNet devices before 3.216. Thr…9.8
- CVE-2023-31472An issue was discovered on GL.iNet devices before 3.216. The…7.5
- CVE-2023-31474An issue was discovered on GL.iNet devices before 3.216. Thr…7.5
- CVE-2023-31475An issue was discovered on GL.iNet devices before 3.216. The…9.8
- CVE-2023-31476An issue was discovered on GL.iNet devices running firmware …7.5
- CVE-2023-31477A path traversal issue was discovered on GL.iNet devices bef…7.5
- CVE-2023-31478An issue was discovered on GL.iNet devices before 3.216. An …7.5
- CVE-2023-3148A vulnerability was found in SourceCodester Online Discussio…8.8
Are you affected by CVE-2023-31473?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
