CVE-2004-2606
Summary
| CVE | CVE-2004-2606 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Linksys | Befsr41 V3 | All | All | All | All |
| Hardware | Linksys | Wrt54g | 2.02.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ftp.linksys.com/pub/network/wrt54g_2.02.8_US_code_beta.zip | af854a3a-2127-422b-91ae-364da2661108 | ftp.linksys.com | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| archives.neohapsis.com/archives/bugtraq/2004-06/0020.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Linksys WRT54G Router World Accessible Remote Administration Service Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Secunia - Advisories - Linksys Routers Administrative Web Interface Access Security Issue | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Confusion surrounds Cisco-Linksys wireless hole | af854a3a-2127-422b-91ae-364da2661108 | www.nwfusion.com | |
| Linksys: Firmware Upgrades | af854a3a-2127-422b-91ae-364da2661108 | web.archive.org | Patch |
| www.osvdb.org/6577 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| archives.neohapsis.com/archives/bugtraq/2004-06/0190.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Neohapsis Archives - Bugtraq - #0316 - LinkSys WRT54G administration page availble to WAN | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| archives.neohapsis.com/archives/bugtraq/2004-06/0002.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.