CVE-2022-43972: Null pointer dereference in Linksys WRT54GL
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soapaction function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43972?
CVE-2022-43972 is a null pointer dereference vulnerability in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006.
What is the severity of CVE-2022-43972?
The severity of CVE-2022-43972 is high with a CVSS score of 7.5.
How does CVE-2022-43972 affect Linksys WRT54GL Wireless-G Broadband Router?
CVE-2022-43972 affects Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006.
How can an attacker exploit CVE-2022-43972?
An unauthenticated attacker can exploit CVE-2022-43972 by sending a malicious POST request invoking the AddPort function.
Is there a fix available for CVE-2022-43972?
There is no information available on a fix for CVE-2022-43972 at the moment.