CVE-2022-43973EPSS p76.4%
CVE-2022-43973CVE-2022-43973
linksys / wrt54gl_firmware
Description
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request to /apply.cgi to execute arbitrary commands on the underlying Linux operating system as root.
Scoring
| CVSS | 7.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.85% probability of exploitation · percentile 76.4% · 2026-06-18T12:00:27Z |
| Last modified | 2026-06-17 |