Vulnerability record · CVE-2023-46455 · published 12 December 2023
CVE-2023-46455: GL.iNet GL-AR300M OpenVPN upload path traversal arbitrary file write
Gl Inet · Gl Ar300m Firmware
GL.iNet GL-AR300M routers running firmware v4.3.7 allow arbitrary file writes via a path traversal flaw in the OpenVPN client file upload feature. Because the write is unauthenticated and network-reachable, an attacker can place files anywhere the service can write, which matters for device integrity and potential follow-on compromise.
Description
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file write on an internet-facing router with a high EPSS score, though no KEV listing or confirmed public exploit in this record.
What it is
GL.iNet GL-AR300M routers running firmware v4.3.7 allow arbitrary file writes via a path traversal flaw in the OpenVPN client file upload feature. Because the write is unauthenticated and network-reachable, an attacker can place files anywhere the service can write, which matters for device integrity and potential follow-on compromise.
Impact
An attacker gains the ability to write arbitrary files on the router, which can corrupt configuration or plant files that alter device behavior. The CVSS vector shows high integrity impact with no confidentiality or availability impact.
Attack surface
Reached over the network through the OpenVPN client file upload functionality; the CVSS vector indicates no authentication (PR:N) and no user interaction (UI:N) are required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.47 (98.8th percentile), and the only reference tags are Third Party Advisory and Product, so no public exploit code is confirmed by this record.
What to do
- Apply the vendor firmware update for GL-AR300M that addresses the OpenVPN upload path traversal; check GL.iNet advisories for the fixed version.
- If no patch is available, disable or restrict the OpenVPN client file upload feature and avoid exposing the router management interface to untrusted networks.
- Restrict network access to the router's web/management services to trusted management networks only.
- Monitor router filesystem and configuration for unexpected changes and reflash firmware if compromise is suspected.
Detection
- Review router logs for OpenVPN client upload requests containing path traversal sequences such as ../.
- Monitor for unexpected or modified files in router filesystem paths writable by the web service.
- Alert on upload activity to the OpenVPN client upload endpoint from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cyberaz0r.info/2023/11/glinet-multiple-vulnerabilities/ | Third Party Advisory |
| https://www.gl-inet.com/ | Product |
| https://cyberaz0r.info/2023/11/glinet-multiple-vulnerabilities/ | Third Party Advisory |
| https://www.gl-inet.com/ | Product |
Track CVE-2023-46455 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46455), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.