Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
BID:19347
Info
Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
| Bugtraq ID: | 19347 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2006 12:00AM |
| Updated: | Nov 22 2006 04:00PM |
| Credit: | Ginsu Rabbit is credited with the discovery of this vulnerability. |
| Vulnerable: |
Linksys WRT54G v1.0 1.0.9 (Firmware) |
| Not Vulnerable: |
Linksys WRT54H 4.71.1 Linksys WRT54G v5 1.0.10 (Firmware) |
Discussion
Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
Linksys WRT54GS is prone to an authentication-bypass vulnerability. Reportedly, the device permits changes in its configuration settings without requring authentication.
Linksys WRT54GS is prone to an authentication-bypass vulnerability. The problem presents itself when a victim user visits a specially crafted web page on an attacker-controlled site. An attacker can exploit this vulnerability to bypass authentication and modify the configuration settings of the device.
This issue is reported to affect firmware version 1.00.9; other firmware versions may also be affected.
Linksys WRT54GS is prone to an authentication-bypass vulnerability. Reportedly, the device permits changes in its configuration settings without requring authentication.
Linksys WRT54GS is prone to an authentication-bypass vulnerability. The problem presents itself when a victim user visits a specially crafted web page on an attacker-controlled site. An attacker can exploit this vulnerability to bypass authentication and modify the configuration settings of the device.
This issue is reported to affect firmware version 1.00.9; other firmware versions may also be affected.
Exploit / POC
Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
Attackers may exploit this issue using a command-line tool (such as 'curl') for transferring files with URL syntax.
A sample exploit 'curl' command line has been provided:
Attackers may exploit this issue using a command-line tool (such as 'curl') for transferring files with URL syntax.
A sample exploit 'curl' command line has been provided:
Solution / Fix
Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
Solution:
The vendor has released an update addressing this issue. Please contact the vendor for information on how to obtain and apply this update.
Solution:
The vendor has released an update addressing this issue. Please contact the vendor for information on how to obtain and apply this update.
References
Linksys WRT54GS POST Request Configuration Change Authentication Bypass Vulnerability
References:
References:
- Linksys Homepage (Linksys)
- linksys wrt54g v5 authentication bypass fixed (Ginsu Rabbit)