Linksys WRT54G Wireless Router Default SSL Certificate and Private Key Vulnerability
BID:14407
Info
Linksys WRT54G Wireless Router Default SSL Certificate and Private Key Vulnerability
| Bugtraq ID: | 14407 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2005 12:00AM |
| Updated: | Jul 28 2005 12:00AM |
| Credit: | Discovery is credited to Nick Simicich <[email protected]>. |
| Vulnerable: |
Linksys WRT54G v2.0 2.0 2.8 beta(Firmware) Linksys WRT54G v2.0 2.0 0.8 (Firmware) Linksys WPC300N - Wireless-N Notebook Adapter 4.100.15.5 |
| Not Vulnerable: | |
Discussion
Linksys WRT54G Wireless Router Default SSL Certificate and Private Key Vulnerability
Linksys WRT54G wireless routers contain a default SSL certificate and private key.
This constant certificate/key pair is always used to access the device.
This can allow an attacker to obtain the certificate/key pair and carry out various attacks.
A complete compromise of the device is possible.
Linksys WRT54G wireless routers contain a default SSL certificate and private key.
This constant certificate/key pair is always used to access the device.
This can allow an attacker to obtain the certificate/key pair and carry out various attacks.
A complete compromise of the device is possible.
Exploit / POC
Linksys WRT54G Wireless Router Default SSL Certificate and Private Key Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Linksys WRT54G Wireless Router Default SSL Certificate and Private Key Vulnerability
Solution:
Reportedly, the vendor has addressed this issue in recent versions of the firmware. Symantec could not confirm this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly, the vendor has addressed this issue in recent versions of the firmware. Symantec could not confirm this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linksys WRT54G Wireless Router Default SSL Certificate and Private Key Vulnerability
References:
References:
- WRT54G Product Page (Linksys)
- Vulnerability in Linksys Router access (Nick Simicich
)