CVE-2007-5474 describes a denial-of-service vulnerability in the Linksys WRT350N Wi-Fi access point with firmware 2.00.17, specifically affecting the Atheros AR5416-AC1E chipset. The flaw stems from improper parsing of the Atheros vendor-specific information element in an association request. An authenticated attacker can exploit this by sending an Atheros information element with an invalid, excessively long length, leading to a device reboot, hang, or potentially arbitrary code execution. The vulnerability has a CVSS score of 6.3 (Medium), indicating a network-based attack with medium complexity requiring authentication, resulting in a complete loss of availability. While the EPSS score is low, suggesting a low probability of exploitation in the wild, the FAUCET Risk Score is 38/100. Currently, there is no known active exploitation of this vulnerability, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:atheros:ar5416-ac1e_chipset:*:*:*:*:*:*:*:* | ||
2.00.17CPE matchmatch criteria | cpe:2.3:h:linksys:wrt350n:2.00.17:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.