Path Traversal Vulnerability in GL.iNet Devices
CVE-2023-31477
7.5HIGH
What is CVE-2023-31477?
A path traversal vulnerability has been identified in GL.iNet devices prior to version 3.216. This flaw allows unauthorized users to exploit the file sharing feature, enabling them to share arbitrary directories, including sensitive system directories like /tmp and /etc. The absence of server-side restrictions to confine sharing solely to the designated USB path poses significant security risks, potentially exposing critical system files and configurations. Addressing this issue is essential to maintain the integrity of GL.iNet devices and safeguard against unauthorized access.
