Command Injection Vulnerability in GL.iNet Devices
CVE-2023-31473
4.9MEDIUM
What is CVE-2023-31473?
A command injection vulnerability was found in GL.iNet devices running software versions prior to 3.216. This flaw allows attackers to exploit the software installation feature to inject arbitrary parameters into a request. By doing so, malicious actors can manipulate the system to create an empty file anywhere within the filesystem due to a flawed filter mechanism. The potential for using 'opkg' with root privileges escalates the severity, as it lets unauthorized users read or modify sensitive configuration files by specifying arbitrary filenames.
