do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
Conclusion & alert: CVE-2022-31793 is rated High Exploit Risk (80.4/100): CVSS High severity, with high exploitation likelihood (EPSS 93.82%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-14 | 93.35% | 93.82% | +0.47% |
| 2 | 2026-02-03 | 93.82% | 93.35% | -0.47% |
| 3 | 2025-11-21 | — | 93.82% | — |
Full EPSS history (30 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| inglorion | muhttpd | < 1.1.7 | cpe:2.3:a:inglorion:muhttpd:*:*:*:*:*:*:*:* |
| arris | nvg443_firmware | — | cpe:2.3:o:arris:nvg443_firmware:-:*:*:*:*:*:*:* |
| arris | nvg599_firmware | — | cpe:2.3:o:arris:nvg599_firmware:-:*:*:*:*:*:*:* |
| arris | nvg589_firmware | — | cpe:2.3:o:arris:nvg589_firmware:-:*:*:*:*:*:*:* |
| arris | nvg510_firmware | — | cpe:2.3:o:arris:nvg510_firmware:-:*:*:*:*:*:*:* |
| arris | bgw210_firmware | — | cpe:2.3:o:arris:bgw210_firmware:-:*:*:*:*:*:*:* |
| arris | bgw320_firmware | — | cpe:2.3:o:arris:bgw320_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://inglorion.net/software/muhttpd/ | Third Party Advisory |
| https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/08/millions-of-arris-routers-are-vulnerable-to-path-traversal-attacks/ | Third Party Advisory |
| https://derekabdine.com/blog/2022-arris-advisory | Exploit Third Party Advisory |
| https://kb.cert.org/vuls/id/495801 | Third Party Advisory US Government Resource |
| https://www.kb.cert.org/vuls/id/495801 |