vendor:
GL.iNet
by:
Michele 'cyberaz0r' Di Bonaventura
6.1
CVSS
HIGH
Arbitrary File Write
269
CWE
Product Name: GL.iNet
Affected Version From: <= 4.3.7
Affected Version To: 4.3.2007
Patch Exists: NO
Related CWE: CVE-2023-46455
CPE: o:gl-inet:gl-inet_firmware:4.3.7
Platforms Tested: GL.iNet AR300M
2023
GL.iNet <= 4.3.7 Arbitrary File Write
The GL.iNet <= 4.3.7 allows an attacker to write arbitrary files on the system by exploiting a vulnerability in the '/upload' endpoint. By crafting a malicious shadow file, an attacker can change the root user's password and gain unauthorized access to the system. This vulnerability has been assigned the CVE-2023-46455.
Mitigation:
To mitigate this vulnerability, it is recommended to update the GL.iNet firmware to version 4.3.8 or higher. Additionally, restrict access to the '/upload' endpoint and implement proper input validation.