Linksys WRT54G Wireless-G Router Multiple Remote Authentication Bypass Vulnerabilities
BID:28381
Info
Linksys WRT54G Wireless-G Router Multiple Remote Authentication Bypass Vulnerabilities
| Bugtraq ID: | 28381 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1247 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2008 12:00AM |
| Updated: | Apr 29 2009 08:56PM |
| Credit: | meathive is credited with the discovery of these issues. |
| Vulnerable: |
Linksys WRT54G v1.0 1.0.9 (Firmware) |
| Not Vulnerable: | |
Discussion
Linksys WRT54G Wireless-G Router Multiple Remote Authentication Bypass Vulnerabilities
Linksys WRT54G Wireless-G Router is prone to multiple authentication-bypass vulnerabilities.
Successful exploits will allow unauthorized attackers to gain access to administrative functionality and completely compromise vulnerable devices; other attacks are also possible.
The issues affect firmware v1.00.9; other versions may also be vulnerable.
Linksys WRT54G Wireless-G Router is prone to multiple authentication-bypass vulnerabilities.
Successful exploits will allow unauthorized attackers to gain access to administrative functionality and completely compromise vulnerable devices; other attacks are also possible.
The issues affect firmware v1.00.9; other versions may also be vulnerable.
Exploit / POC
Linksys WRT54G Wireless-G Router Multiple Remote Authentication Bypass Vulnerabilities
Attackers can use readily available tools to exploit these issues.
The following proof-of-concept code is available:
Attackers can use readily available tools to exploit these issues.
The following proof-of-concept code is available:
Solution / Fix
Linksys WRT54G Wireless-G Router Multiple Remote Authentication Bypass Vulnerabilities
Solution:
Reports indicate that the vendor has released fixes, but Symantec was unable to confirm this.
Solution:
Reports indicate that the vendor has released fixes, but Symantec was unable to confirm this.
References
Linksys WRT54G Wireless-G Router Multiple Remote Authentication Bypass Vulnerabilities
References:
References:
- Linksys Homepage (Linksys)