Linksys Vulnerabilities and Affected Products
Vulnerabilities associated with WRT54GL Wireless-G Broadband Router.
Products
Clear product- RE700058 vulnerabilities
- RE625057 vulnerabilities
- RE630057 vulnerabilities
- RE635057 vulnerabilities
- RE650057 vulnerabilities
- RE900057 vulnerabilities
- MR96008 vulnerabilities
- MX42006 vulnerabilities
- E17004 vulnerabilities
- e1700_firmware3 vulnerabilities
- e5600_firmware3 vulnerabilities
- ESeries E12003 vulnerabilities
- ESeries E25003 vulnerabilities
- WRT54GL3 vulnerabilities
- WRT54GL Wireless-G Broadband Router3 vulnerabilities
- E20002 vulnerabilities
- E32002 vulnerabilities
- EA75002 vulnerabilities
- FGW3000-AH2 vulnerabilities
- FGW3000-HK2 vulnerabilities
- re6500_firmware2 vulnerabilities
- wrt54g2 vulnerabilities
- E-Series Routers1 vulnerability
- E10001 vulnerability
- E1000 v11 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-43970HIGH | Buffer overflow in Linksys WRT54GLA buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux operating system as root. This vulnerablity can be triggered over the network via a malicious POST request to /apply.cgi. | CVSS7.2v3.1 | EPSS19.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43973HIGH | Arbitrary code execution in Linksys WRT54GLAn arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request to /apply.cgi to execute arbitrary commands on the underlying Linux operating system as root. CWE-78Jan 9, 2023 | CVSS7.2v3.1 | EPSS1.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43972MEDIUM | Null pointer dereference in Linksys WRT54GLA null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action. CWE-476Jan 9, 2023 | CVSS6.5v3.1 | EPSS1.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |