Vulnerability Details CVE-2023-46456
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.247
EPSS Ranking 97.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-46456
-
cpe:2.3:h:gl-inet:gl-ar300m:-
-
cpe:2.3:o:gl-inet:gl-ar300m_firmware:3.216