An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-29T20:22:03.399Z
Reserved: 2023-04-28T00:00:00.000Z
Link: CVE-2023-31476

Updated: 2024-08-02T14:53:30.868Z

Status : Modified
Published: 2023-05-09T16:15:14.680
Modified: 2025-01-29T21:15:20.103
Link: CVE-2023-31476

No data.