PT-2023-14414 · Linksys · Linksys Wrt54Gl Wireless-G Broadband Router

Jessie Chick

·

Published

2023-01-09

·

Updated

2023-01-13

·

CVE-2022-43972

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linksys WRT54GL Wireless-G Broadband Router versions <= 4.30.18.006
Description A null pointer dereference issue exists in the soap action function within the upnp binary. This can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.
Recommendations For versions <= 4.30.18.006, update the firmware to a version higher than 4.30.18.006 to resolve the issue. As a temporary workaround, consider restricting access to the upnp binary to minimize the risk of exploitation. Avoid using the AddPortMapping action in the affected API endpoint until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2022-43972

Affected Products

Linksys Wrt54Gl Wireless-G Broadband Router