← Vulnerability feed

Vulnerability record · CVE-2023-46455 · published 12 December 2023

CVE-2023-46455: GL.iNet GL-AR300M OpenVPN upload path traversal arbitrary file write

Gl Inet · Gl Ar300m Firmware

GL.iNet GL-AR300M routers running firmware v4.3.7 allow arbitrary file writes via a path traversal flaw in the OpenVPN client file upload feature. Because the write is unauthenticated and network-reachable, an attacker can place files anywhere the service can write, which matters for device integrity and potential follow-on compromise.

7.5 CVSS 3.1 High EPSS 47% · top 1.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file write on an internet-facing router with a high EPSS score, though no KEV listing or confirmed public exploit in this record.

What it is

GL.iNet GL-AR300M routers running firmware v4.3.7 allow arbitrary file writes via a path traversal flaw in the OpenVPN client file upload feature. Because the write is unauthenticated and network-reachable, an attacker can place files anywhere the service can write, which matters for device integrity and potential follow-on compromise.

Impact

An attacker gains the ability to write arbitrary files on the router, which can corrupt configuration or plant files that alter device behavior. The CVSS vector shows high integrity impact with no confidentiality or availability impact.

Attack surface

Reached over the network through the OpenVPN client file upload functionality; the CVSS vector indicates no authentication (PR:N) and no user interaction (UI:N) are required.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.47 (98.8th percentile), and the only reference tags are Third Party Advisory and Product, so no public exploit code is confirmed by this record.

What to do

  • Apply the vendor firmware update for GL-AR300M that addresses the OpenVPN upload path traversal; check GL.iNet advisories for the fixed version.
  • If no patch is available, disable or restrict the OpenVPN client file upload feature and avoid exposing the router management interface to untrusted networks.
  • Restrict network access to the router's web/management services to trusted management networks only.
  • Monitor router filesystem and configuration for unexpected changes and reflash firmware if compromise is suspected.

Detection

  • Review router logs for OpenVPN client upload requests containing path traversal sequences such as ../.
  • Monitor for unexpected or modified files in router filesystem paths writable by the web service.
  • Alert on upload activity to the OpenVPN client upload endpoint from untrusted source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-46455 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-50919GL.iNet router NGINX authentication bypass via Lua pattern matchingGL.iNet devices before firmware 4.5.0 contain an authentication bypass in the NGINX web interface caused by improper Lua string pattern matching. A r…EPSS 48%analysed9.8CVE-2023-50921Gl-inet gl-mt1300 firmware improper privilege management vulnerabilityAn issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. T…EPSS 0.52%9.8CVE-2023-46454Gl-inet gl-ar300m firmware os command injection vulnerabilityIn GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package in…EPSS 23%9.8CVE-2023-46456Gl-inet gl-ar300m firmware injection vulnerabilityIn GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionali…EPSS 25%9.8CVE-2023-31475Gl-inet gl-s20 firmware classic buffer overflow vulnerabilityAn issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is request…EPSS 14%9.8CVE-2023-31471Gl-inet gl-s20 firmware vulnerabilityAn issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, suc…EPSS 1.1%7.8CVE-2023-50445Gl-inet gl-mt1300 firmware os command injection vulnerabilityShell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N…EPSS 9.1%7.5CVE-2023-31477Gl-inet gl-s20 firmware path traversal vulnerabilityA path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directo…EPSS 0.94%

Source: NIST National Vulnerability Database (record CVE-2023-46455), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.