VYPR
High severity7.2NVD Advisory· Published Jan 9, 2023· Updated Jun 17, 2026

CVE-2022-43971

CVE-2022-43971

Description

An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious GET or POST request to /setNTP.cgi to execute arbitrary commands on the underlying Linux operating system as root.

Affected products

5
  • cpe:2.3:o:linksys:wumc710_firmware:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linksys:wumc710_firmware:*:*:*:*:*:*:*:*range: <1.0.02
    • cpe:2.3:o:linksys:wumc710_firmware:1.0.02:-:*:*:*:*:*:*
    • cpe:2.3:o:linksys:wumc710_firmware:1.0.02:build3:*:*:*:*:*:*
  • <=1.0.02 (build3)+ 1 more
    • (no CPE)range: <=1.0.02 (build3)
    • (no CPE)range: Firmware

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.