CVE-2023-47464
HIGHGL.iNet AX1800 4.0.0-4.4.9 - Unauthenticated Arbitrary File Write via Upload API
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-47464. PoCs published by HadessCS.
AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2023-47464, targeting GL-iNet AX1800 routers via an insecure file upload vulnerability leading to path traversal and potential RCE. The PoC demonstrates file upload to arbitrary locations via the `/upload` endpoint.
Description
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function.
Exploits (1)
The repository contains a functional Python exploit for CVE-2023-47464, targeting GL-iNet AX1800 routers via an insecure file upload vulnerability leading to path traversal and potential RCE. The PoC demonstrates file upload to arbitrary locations via the `/upload` endpoint.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H