CVE-2004-2606
Summary
| CVE | CVE-2004-2606 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2017-07-11 01:32:00 UTC |
| Description | The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Linksys | Befsr41 V3 | All | All | All | All |
| Hardware | Linksys | Befsr41 V3 | All | All | All | All |
| Hardware | Linksys | Wrt54g | 2.02.7 | All | All | All |
| Hardware | Linksys | Wrt54g | 2.02.7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 20040601 Re: LinkSys WRT54G administration page availble to WAN | BUGTRAQ | archives.neohapsis.com | |
| Secunia - Advisories - Linksys Routers Administrative Web Interface Access Security Issue | SECUNIA | secunia.com | Patch, Vendor Advisory |
| 20040602 Additional information on WRT54G administration page | BUGTRAQ | archives.neohapsis.com | |
| Neohapsis Archives - Bugtraq - #0316 - LinkSys WRT54G administration page availble to WAN | BUGTRAQ | archives.neohapsis.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 20040602 Re: The Linksys WRT54G "security problem" doesn't exist | BUGTRAQ | archives.neohapsis.com | |
| Confusion surrounds Cisco-Linksys wireless hole | MISC | www.nwfusion.com | |
| Linksys WRT54G Router World Accessible Remote Administration Service Weakness | BID | www.securityfocus.com | Patch |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 6577 | OSVDB | www.osvdb.org | |
| ftp.linksys.com/pub/network/wrt54g_2.02.8_US_code_beta.zip | CONFIRM | ftp.linksys.com | Patch |
| Linksys: Firmware Upgrades | MISC | web.archive.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.