AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-43971

HIGH · CVSS 7.2 EPSS 1.68%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-43971
Severity
HIGH
CVSS
7.2
EPSS
1.68%
Linux

Original NVD Description

An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious GET or POST request to /setNTP.cgi to execute arbitrary commands on the underlying Linux operating system as root.