CVE-2022-31793

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
04/08/2022
Last modified:
11/08/2022

Description

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:inglorion:muhttpd:*:*:*:*:*:*:*:* 1.1.7 (excluding)
cpe:2.3:o:arris:nvg443_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arris:nvg443:-:*:*:*:*:*:*:*
cpe:2.3:o:arris:nvg599_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arris:nvg599:-:*:*:*:*:*:*:*
cpe:2.3:o:arris:nvg589_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arris:nvg589:-:*:*:*:*:*:*:*
cpe:2.3:o:arris:nvg510_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arris:nvg510:-:*:*:*:*:*:*:*
cpe:2.3:o:arris:bgw210_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arris:bgw210:-:*:*:*:*:*:*:*
cpe:2.3:o:arris:bgw320_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arris:bgw320:-:*:*:*:*:*:*:*