PoC Index

CVE-2022-31793

HIGH 7.5EPSS 15.9%

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
15.85% chance of exploitation in the next 30 days, 97th percentile
Nuclei
high · CWE-22
Published
2022-08-04
Updated
2024-08-03

Proof-of-concept exploits (3)

Nuclei templates (1)

Exploit collections (1)

References

Related