CVE-2023-31476

HIGH

GL.iNet GL-MV1000W and GL-MV1000 Firmware < 3.215 - Arbitrary File Write via Limited Path Injection

Title source: llm
STIX 2.1

Description

An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).

Scores

CVSS v3 7.5
EPSS 0.0080
EPSS Percentile 52.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (2)
gl-inet/gl-mv1000_firmware < 3.215
gl-inet/gl-mv1000w_firmware < 3.215
Published May 09, 2023
Tracked Since Feb 18, 2026