CVE-2022-31793
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
La función do_request en el archivo request.c en muhttpd versiones anteriores a 1.1.7, permite a atacantes remotos leer archivos arbitrarios al construir una URL con un solo carácter antes de una ruta deseada en el sistema de archivos. Esto ocurre porque el código salta el primer carácter cuando sirve archivos. Los dispositivos Arris NVG443, NVG599, NVG589 y NVG510 y los dispositivos derivados de Arris BGW210 y BGW320 están afectados
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-27 CVE Reserved
- 2022-08-04 CVE Published
- 2022-08-19 First Exploit
- 2024-08-03 CVE Updated
- 2024-10-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://inglorion.net/software/muhttpd | Third Party Advisory | |
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/08/millions-of-arris-routers-are-vulnerable-to-path-traversal-attacks | Third Party Advisory | |
https://kb.cert.org/vuls/id/495801 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/xpgdgit/CVE-2022-31793 | 2022-08-19 | |
https://derekabdine.com/blog/2022-arris-advisory | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arris Search vendor "Arris" | Nvg443 Firmware Search vendor "Arris" for product "Nvg443 Firmware" | - | - |
Affected
| in | Arris Search vendor "Arris" | Nvg443 Search vendor "Arris" for product "Nvg443" | - | - |
Safe
|
Arris Search vendor "Arris" | Nvg599 Firmware Search vendor "Arris" for product "Nvg599 Firmware" | - | - |
Affected
| in | Arris Search vendor "Arris" | Nvg599 Search vendor "Arris" for product "Nvg599" | - | - |
Safe
|
Arris Search vendor "Arris" | Nvg589 Firmware Search vendor "Arris" for product "Nvg589 Firmware" | - | - |
Affected
| in | Arris Search vendor "Arris" | Nvg589 Search vendor "Arris" for product "Nvg589" | - | - |
Safe
|
Arris Search vendor "Arris" | Nvg510 Firmware Search vendor "Arris" for product "Nvg510 Firmware" | - | - |
Affected
| in | Arris Search vendor "Arris" | Nvg510 Search vendor "Arris" for product "Nvg510" | - | - |
Safe
|
Arris Search vendor "Arris" | Bgw210 Firmware Search vendor "Arris" for product "Bgw210 Firmware" | - | - |
Affected
| in | Arris Search vendor "Arris" | Bgw210 Search vendor "Arris" for product "Bgw210" | - | - |
Safe
|
Arris Search vendor "Arris" | Bgw320 Firmware Search vendor "Arris" for product "Bgw320 Firmware" | - | - |
Affected
| in | Arris Search vendor "Arris" | Bgw320 Search vendor "Arris" for product "Bgw320" | - | - |
Safe
|
Inglorion Search vendor "Inglorion" | Muhttpd Search vendor "Inglorion" for product "Muhttpd" | < 1.1.7 Search vendor "Inglorion" for product "Muhttpd" and version " < 1.1.7" | - |
Affected
|