Record summary

CVE-2023-46455 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List4.3.7affected

Proofs of concept

1

Repository PoCs

GitHubcyberaz0r/GL.iNet-Multiple-VulnerabilitiesRepository PoCby cyberaz0rStars: 3Not analyzed4 files

10.9 KiB · linked to 3 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHGL.iNet <= 4.3.7 - Arbitrary File WriteCVSS 7.5

GL.iNet <= 4.3.7 is vulnerable to an arbitrary file write exploit, allowing an attacker to overwrite arbitrary system files.

Impact

Unauthenticated attackers can overwrite arbitrary system files, potentially compromising the device configuration and enabling persistent access.

Remediation

Upgrade GL.iNet devices to firmware version 4.3.8 or later.

WeaknessesCWE-22
AuthorsZierax
Template tagscvecve2023gl-netfile-uploadintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CPE: cpe:2.3:o:gl-inet:gl-ar300m_firmware:4.3.7:*:*:*:*:*:*:*
Shodan: title:"GL.iNet Admin Panel"

Source: ProjectDiscovery

References

3