CVE-2023-31477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
11/05/2023
Last modified:
27/01/2025

Description

A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gl-inet:gl-s20_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)
cpe:2.3:h:gl-inet:gl-s20:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-x3000_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)
cpe:2.3:h:gl-inet:gl-x3000:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)
cpe:2.3:h:gl-inet:gl-mt3000:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt2500_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)
cpe:2.3:h:gl-inet:gl-mt2500:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-mt2500a_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)
cpe:2.3:h:gl-inet:gl-mt2500a:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-axt1800_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)
cpe:2.3:h:gl-inet:gl-axt1800:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-a1300_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)
cpe:2.3:h:gl-inet:gl-a1300:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-ax1800_firmware:*:*:*:*:*:*:*:* 3.216 (excluding)