Vulnerability Details CVE-2023-46456
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.139
EPSS Ranking 94.0%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-46456
-
cpe:2.3:h:gl-inet:gl-ar300m:-
-
cpe:2.3:o:gl-inet:gl-ar300m_firmware:3.216