In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
No PoCs from references.
- https://github.com/cyberaz0r/GL.iNet-Multiple-Vulnerabilities