do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
2022-08-04T22:15:08.017
2024-11-21T07:05:20.330
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | inglorion | muhttpd | < 1.1.7 | Yes |
Operating System | arris | nvg443_firmware | - | Yes |
Hardware | arris | nvg443 | - | No |
Operating System | arris | nvg599_firmware | - | Yes |
Hardware | arris | nvg599 | - | No |
Operating System | arris | nvg589_firmware | - | Yes |
Hardware | arris | nvg589 | - | No |
Operating System | arris | nvg510_firmware | - | Yes |
Hardware | arris | nvg510 | - | No |
Operating System | arris | bgw210_firmware | - | Yes |
Hardware | arris | bgw210 | - | No |
Operating System | arris | bgw320_firmware | - | Yes |
Hardware | arris | bgw320 | - | No |