VDB
CVE-2022-31793
CVE-2022-31793
PUBLISHED
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
EPSS 15.85% · 96.6th percentile
Risk Scores
EPSS Score
15.85%
96.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| arris | nvg589_firmware | |
| arris | bgw210_firmware | |
| inglorion | muhttpd | 0 |
| arris | nvg510_firmware | |
| n/a | n/a | n/a |
| arris | nvg443_firmware | |
| arris | bgw320_firmware | |
| arris | nvg599_firmware |
Timeline
- Aug 4, 2022 CVE Published
- Aug 5, 2022 EPSS Score
- Sep 20, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Feb 7, 2023 EPSS Score
- Mar 23, 2023 EPSS Score
- Mar 25, 2023 EPSS Score
- May 8, 2023 EPSS Score
- Jun 26, 2023 EPSS Score
- Jul 5, 2023 EPSS Score
- Sep 6, 2023 EPSS Score
- Nov 12, 2023 EPSS Score
References
- http://inglorion.net/software/muhttpd/ url
- https://kb.cert.org/vuls/id/495801 url
- https://derekabdine.com/blog/2022-arris-advisory url
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/08/millions-of-arris-routers-are-vulnerable-to-path-traversal-attacks/ url
- https://www.kb.cert.org/vuls/id/495801 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-31793 advisory
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/08/millions-of-arris-routers-are-vulnerable-to-path-traversal-attacks url
- http://inglorion.net/software/muhttpd url