CVE-2022-43972
published 2023-01-09CVE-2022-43972: A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linksys | wrt54gl_firmware | <= 4.30.18.006 | — |
| linksys | wrt54gl_wireless-g_broadband_router | Firmware – 4.30.18.006 | — |