Linksys WRT54G Wireless Router Multiple Remote Vulnerabilities
BID:14822
Info
Linksys WRT54G Wireless Router Multiple Remote Vulnerabilities
| Bugtraq ID: | 14822 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2005 12:00AM |
| Updated: | Sep 13 2005 12:00AM |
| Credit: | These vulnerabilities were discovered by Greg MacManus of iDEFENSE Labs. |
| Vulnerable: |
Linksys WRT54G v4.0 4.20.6 (Firmware) Linksys WRT54G v4.0 4.0.7 (Firmware) Linksys WRT54G v3.0 3.3.6 (Firmware) Linksys WRT54G v3.0 3.1.3 (Firmware) Linksys WRT54G v2.0 2.4.4 (Firmware) |
| Not Vulnerable: | |
Discussion
Linksys WRT54G Wireless Router Multiple Remote Vulnerabilities
Multiple vulnerabilities have been identified in Linksys WRT54G routers. These issue all require that an attacker have access to either the wireless, or internal LAN network segments of the affected device. Exploitation from the WAN interface is only possible if the affected device has remote management enabled.
This issue allows attackers to:
- Download and replace the configuration of affected routers.
- Execute arbitrary machine code in the context of the affected device.
- Utilize HTTP POST requests to upload router configuration and firmware files without proper authentication
- Degrade the performance of affected devices and cause the Web server to become unresponsive, potentially denying service to legitimate users.
Multiple vulnerabilities have been identified in Linksys WRT54G routers. These issue all require that an attacker have access to either the wireless, or internal LAN network segments of the affected device. Exploitation from the WAN interface is only possible if the affected device has remote management enabled.
This issue allows attackers to:
- Download and replace the configuration of affected routers.
- Execute arbitrary machine code in the context of the affected device.
- Utilize HTTP POST requests to upload router configuration and firmware files without proper authentication
- Degrade the performance of affected devices and cause the Web server to become unresponsive, potentially denying service to legitimate users.
Exploit / POC
Linksys WRT54G Wireless Router Multiple Remote Vulnerabilities
An exploit is not required for most of these vulnerabilities.
Currently we are not aware of any exploits for the buffer overflow issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
An exploit is not required for most of these vulnerabilities.
Currently we are not aware of any exploits for the buffer overflow issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linksys WRT54G Wireless Router Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linksys WRT54G Wireless Router Multiple Remote Vulnerabilities
References:
References:
- Linksys Homepage (Linksys)
- Linksys WRT54G 'restore.cgi' Configuration Modification Design Error Vulnerabili (iDEFENSE)
- Linksys WRT54G 'upgrade.cgi' Firmware Upload Design Error Vulnerability (iDEFENSE)
- Linksys WRT54G Management Interface DoS Vulnerability (iDEFENSE)
- Linksys WRT54G Router Remote Administration apply.cgi Buffer Overflow Vulnerabil (iDEFENSE)
- Linksys WRT54G Router Remote Administration Fixed Encryption Key Vulnerability (iDEFENSE)
- WRT54G Product Page (Linksys)