CVE-2022-43973
published 2023-01-09CVE-2022-43973: An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within…
high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request to /apply.cgi to execute arbitrary commands on the underlying Linux operating system as root.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linksys | wrt54gl_firmware | <= 4.30.18.006 | — |
| linksys | wrt54gl_wireless-g_broadband_router | Firmware – 4.30.18.006 | — |