CVE Feed

    Dashboard / CVE / CVE-2023-31476

    CVE-2023-31476

    An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).

    Published:May 9, 2023
    Last Modified:Jan 29, 2025
    EPS:May 9, 2023
    EPSS Score:0.00071
    CVSS Score:7.5

    Affected Products

    Vendor
    Gl-inet
    Product
    Gl-mv1000
    Vendor
    Gl-inet
    Product
    Gl-mv1000 Firmware
    Vendor
    Gl-inet
    Product
    Gl-mv1000w
    Vendor
    Gl-inet
    Product
    Gl-mv1000w Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High