Linksys WRT54GS Wireless Authentication Bypass Vulnerability
BID:14566
Info
Linksys WRT54GS Wireless Authentication Bypass Vulnerability
| Bugtraq ID: | 14566 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2005 12:00AM |
| Updated: | Aug 15 2005 12:00AM |
| Credit: | Steve Scherf <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Linksys WRT54GS 4.50.6 (Firmware) |
| Not Vulnerable: |
Linksys WRT54GS 4.70.6 (Firmware) |
Discussion
Linksys WRT54GS Wireless Authentication Bypass Vulnerability
Linksys WRT54GS is prone to an authentication bypass vulnerability. Reportedly the device permits client devices that are using no encryption to connect when an encryption setting is being used.
An attacker can exploit this vulnerability to bypass authentication and connect to a wireless network thought to be encrypted. This results in a false sense of security.
This issue is reported to affect firmware version 4.50.6; other firmware versions may also be affected.
This issue also appears to have been addressed in firmware version 4.70.6; this has not been confirmed by Symantec or the vendor.
Further information suggests this issue occurs when a firmware upgrade to version 4.50.6 has occurred but the unit has not been reset to factory defaults. Resetting the unit once the firmware has been upgraded is part of the recommended Linksys upgrade procedure.
Linksys WRT54GS is prone to an authentication bypass vulnerability. Reportedly the device permits client devices that are using no encryption to connect when an encryption setting is being used.
An attacker can exploit this vulnerability to bypass authentication and connect to a wireless network thought to be encrypted. This results in a false sense of security.
This issue is reported to affect firmware version 4.50.6; other firmware versions may also be affected.
This issue also appears to have been addressed in firmware version 4.70.6; this has not been confirmed by Symantec or the vendor.
Further information suggests this issue occurs when a firmware upgrade to version 4.50.6 has occurred but the unit has not been reset to factory defaults. Resetting the unit once the firmware has been upgraded is part of the recommended Linksys upgrade procedure.
Exploit / POC
Linksys WRT54GS Wireless Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Linksys WRT54GS Wireless Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linksys WRT54GS Wireless Authentication Bypass Vulnerability
References:
References:
- Linksys Homepage (Linksys)
- WRT54GS Product Page (Linksys)
- RE: Serious flaw in Linksys wireless AP password security ("Robert Thompson Jr."
) - Re: Serious flaw in Linksys wireless AP password security (Steve Scherf
) - Serious flaw in Linksys wireless AP password security (Steve Scherf
)