PT-2023-14414 · Linksys · Linksys Wrt54Gl Wireless-G Broadband Router

Jessie Chick

·

Publicado

2023-01-09

·

Atualizado

2023-01-13

·

CVE-2022-43972

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linksys WRT54GL Wireless-G Broadband Router versions <= 4.30.18.006
Description A null pointer dereference issue exists in the soap action function within the upnp binary. This can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.
Recommendations For versions <= 4.30.18.006, update the firmware to a version higher than 4.30.18.006 to resolve the issue. As a temporary workaround, consider restricting access to the upnp binary to minimize the risk of exploitation. Avoid using the AddPortMapping action in the affected API endpoint until the issue is resolved.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-43972

Produtos afetados

Linksys Wrt54Gl Wireless-G Broadband Router