Record summary

CVE-2023-46456 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC.

Description

In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Proofs of concept

1

Repository PoCs

GitHubcyberaz0r/GL.iNet-Multiple-VulnerabilitiesRepository PoCby cyberaz0rStars: 3Not analyzed4 files

10.9 KiB · linked to 3 vulnerabilities

GitHub

PoC details

References

3