VDB

CVE-2022-31793

CVE-2022-31793 PUBLISHED

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

EPSS 15.85% · 96.6th percentile

Risk Scores

EPSS Score
15.85%
96.6th percentile

Affected Products

VendorProductVersions
arrisnvg589_firmware
arrisbgw210_firmware
inglorionmuhttpd0
arrisnvg510_firmware
n/an/an/a
arrisnvg443_firmware
arrisbgw320_firmware
arrisnvg599_firmware

Timeline

  • Aug 4, 2022 CVE Published
  • Aug 5, 2022 EPSS Score
  • Sep 20, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Feb 7, 2023 EPSS Score
  • Mar 23, 2023 EPSS Score
  • Mar 25, 2023 EPSS Score
  • May 8, 2023 EPSS Score
  • Jun 26, 2023 EPSS Score
  • Jul 5, 2023 EPSS Score
  • Sep 6, 2023 EPSS Score
  • Nov 12, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›