vendor:
GL.iNet
by:
Michele 'cyberaz0r' Di Bonaventura
6.1
CVSS
HIGH
Arbitrary File Write
22
CWE
Product Name: GL.iNet
Affected Version From: <= 4.3.7
Affected Version To: 4.3.2007
Patch Exists: NO
Related CWE: CVE-2023-46455
CPE: o:gl-inet:gl-inet_firmware:4.3.7
Platforms Tested: GL.iNet AR300M
2023
GL.iNet <= 4.3.7 Arbitrary File Write
The GL.iNet <= 4.3.7 allows an authenticated attacker to write arbitrary files via a crafted POST request, leading to unauthorized access. This vulnerability has been assigned CVE-2023-46455.
Mitigation:
It is recommended to update the GL.iNet firmware to version 4.3.8 or later to mitigate this arbitrary file write vulnerability.