CVE-2023-31477 Information

Description

A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature it is possible to share an arbitrary directory such as /tmp or /etc because there is no server-side restriction to limit sharing to the USB path.

Reference

https://www.gl-inet.com https://github.com/gl-inet/CVE-issues/blob/main/3.215/Path_Traversal.md

Share on: