logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-43971

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-43971

Description:
An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious GET or POST request to /setNTP.cgi to execute arbitrary commands on the underlying Linux operating system as root.
Last updated date:
01/13/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/13/2023
Reference url to background

https://youtu.be/73-1lhvJPNg

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/13/2023
Reference url to background

https://youtu.be/RfWVYCUBNZ0

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/13/2023
Reference url to background

https://youtu.be/TeWAmZaKQ_w

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy