AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-31473

MEDIUM · CVSS 4.9 EPSS 3.87% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-05-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2023-31473
Severity
MEDIUM
CVSS
4.9
EPSS
3.87%

Original NVD Description

An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.