PT-2023-14412 · Linksys · Linksys Wrt54Gl Wireless-G Broadband Router
Jessie Chick
·
Published
2023-01-09
·
Updated
2023-01-13
·
CVE-2022-43970
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linksys WRT54GL Wireless-G Broadband Router versions <= 4.30.18.006
Description
A buffer overflow issue exists, allowing an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux operating system as root. This can be triggered over the network via a malicious POST request to the
/apply.cgi endpoint. The vulnerability is specifically related to a stack-based buffer overflow in the Start EPI function within the httpd binary.Recommendations
For versions <= 4.30.18.006, as a temporary workaround, consider restricting access to the
/apply.cgi endpoint until a patch is available. Additionally, limiting administrator privileges can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linksys Wrt54Gl Wireless-G Broadband Router