A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.
2023-01-09T21:15:10.920
2024-11-21T07:27:27.420
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linksys | wrt54gl_firmware | ≤ 4.30.18.006 | Yes |
Hardware | linksys | wrt54gl | - | No |