CVE-2023-31742: Command Injection
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wlant, wlrate, WLattenctl, ttcpnum, ttcpsize in the httpd s StartEPI() function, thereby gaining shell privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linksys WRT54GL routerto a version that resolves this vulnerability.Fixed in 4.30.18.006
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-31742.
What is the affected software?
The affected software is Linksys Wrt54gl Firmware with version 4.30.18.006.
How severe is this vulnerability?
This vulnerability has a severity score of 7.2 (high).
How does this vulnerability work?
This vulnerability allows an attacker with web management privileges to inject commands into certain post request parameters, which can result in command execution.
Is there a fix available for this vulnerability?
Currently, there is no official fix or patch available for this vulnerability.