High severity7.2NVD Advisory· Published Jan 9, 2023· Updated Jun 17, 2026
CVE-2022-43971
CVE-2022-43971
Description
An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious GET or POST request to /setNTP.cgi to execute arbitrary commands on the underlying Linux operating system as root.
Affected products
5cpe:2.3:o:linksys:wumc710_firmware:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:linksys:wumc710_firmware:*:*:*:*:*:*:*:*range: <1.0.02
- cpe:2.3:o:linksys:wumc710_firmware:1.0.02:-:*:*:*:*:*:*
- cpe:2.3:o:linksys:wumc710_firmware:1.0.02:build3:*:*:*:*:*:*
<=1.0.02 (build3)+ 1 more
- (no CPE)range: <=1.0.02 (build3)
- (no CPE)range: Firmware
Patches
Vulnerability mechanics
References
3- youtu.be/73-1lhvJPNgnvdExploitThird Party Advisory
- youtu.be/RfWVYCUBNZ0nvdExploitThird Party Advisory
- youtu.be/TeWAmZaKQ_wnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.