Record summary

CVE-2022-31793 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubxpgdgit/CVE-2022-31793Repository PoCby xpgdgitStars: 1Not analyzed4 files

4.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHmuhttpd <=1.1.5 - Local InclusionCVSS 7.5

muhttpd 1.1.5 and before are vulnerable to unauthenticated local file inclusion. The vulnerability allows retrieval of files from the file system.

Impact

An attacker can exploit this vulnerability to read sensitive files on the system.

Remediation

Update the application to version 1.10

WeaknessesCWE-22
Authorsscent2d
Template tagsnetworkcvecve2022muhttpdlfiunauthingloriontcpvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:inglorion:muhttpd:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6