CVE-2022-43973
HIGH 7.2EPSS 1.9%
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request to /apply.cgi to execute arbitrary commands on the underlying Linux operating system as root.
- CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS
- 1.85% chance of exploitation in the next 30 days, 78th percentile
- Published
- 2023-01-09
- Updated
- 2025-04-09
Proof-of-concept exploits (4)
- https://youtu.be/73-1lhvJPNg
- https://youtu.be/RfWVYCUBNZ0
- https://youtu.be/TeWAmZaKQ_w
- UmbertoDellaMonica/Linksys-WRT54GL-Exploitation