S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-31793 Scanner

CVE-2022-31793 scanner - Path Traversal vulnerability in muhttpd

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31793
7.5
CVSS

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Muhttpd is a lightweight web server application that is used to serve files on a network. This software is designed for resource-constrained systems, and it provides a simple and efficient solution for serving web content. Muhttpd is used in a wide range of devices, such as routers, switches, and other embedded systems. It is an essential part of many networking devices as it helps to provide a web interface to access the device settings and configuration options.

CVE-2022-31793 is a critical vulnerability that has been detected in muhttpd. This vulnerability allows remote attackers to read arbitrary files by constructing a URL with a single character before the desired path on the filesystem. The flaw occurs because the server code skips over the first character when serving files. This vulnerability can be exploited to gain unauthorized access to sensitive files on the device, compromising the confidentiality and integrity of the system.

Exploitation of the CVE-2022-31793 vulnerability could lead to significant security risks, including data theft or destruction. Attackers can use it to obtain sensitive information, such as passwords, configuration files, or network topologies. They can also modify system settings or execute commands on the device. This could result in a complete system compromise, leading to far-reaching consequences for both individuals and businesses.

With the pro features of the s4e.io platform, it is effortless and quick to learn about vulnerabilities in digital assets. The platform delivers comprehensive and up-to-date information on the latest security threats, including CVE-2022-31793. Users can access vulnerability information for their devices, perform risk assessments, and implement mitigation measures to protect their assets. The s4e.io platform is an indispensable tool for anyone concerned about digital security, providing peace of mind and comprehensive protection against cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users and system administrators can take the following precautions:

  • Upgrade to the latest version of muhttpd software, which includes a fix for the vulnerability.
  • Apply security patches released by the device manufacturer or platform provider.
  • Restrict access to the web server by disabling unnecessary services and protocols.
  • Configure firewalls to block unauthorized traffic and limit network exposure.
  • Use strong passwords and enable two-factor authentication to prevent unauthorized access to the device.
     

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.