cbcvebase.
CVE-2022-43972
published 2023-01-09

CVE-2022-43972: A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.

Affected

2 ranges
VendorProductVersion rangeFixed in
linksyswrt54gl_firmware<= 4.30.18.006
linksyswrt54gl_wireless-g_broadband_routerFirmware – 4.30.18.006