Broadcom UPnP Software contains a format string flaw in the SetConnectionType() function in the wanppp and wanipc module. The issue is triggered as format string specifiers (e.g. %s and %x) are not properly sanitized in user-supplied input when parsing SOAP requests. With a specially crafted request, a remote attacker can cause a denial of service or potentially execute arbitrary code.