Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52cq-m3mg-849p

Опубликовано: 11 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.

EPSS

Процентиль: 85%
0.02473
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 4.9
nvd
больше 2 лет назад

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.

EPSS

Процентиль: 85%
0.02473
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-77