Linksys DSL Router Default SNMP Community String Vulnerability
BID:3797
Info
Linksys DSL Router Default SNMP Community String Vulnerability
| Bugtraq ID: | 3797 |
| Class: | Design Error |
| CVE: |
CVE-2002-0109 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was announced by Matthew S. Hallacy <[email protected]> via Bugtraq on January 6, 2002. |
| Vulnerable: |
Linksys EtherFast BEFSR81 Router Linksys EtherFast BEFN2PS4 Router |
| Not Vulnerable: | |
Discussion
Linksys DSL Router Default SNMP Community String Vulnerability
Linksys DSL routers are high-speed internet access solutions distributed by the Linksys Group. Linksys DSL routers offer features such as high-speed internet access, switching built into some routers, and Voice-over-IP.
A problem with Linksys routers could make it possible for a remote user to gain sensitive information from a Linksys router. The problem is in the use of a default community string.
Linksys routers include a default community string of "public." By accessing a system using this string, a remote user may be able to gain sensitive information about a network managed by a vulnerable Linksys router.
Linksys DSL routers are high-speed internet access solutions distributed by the Linksys Group. Linksys DSL routers offer features such as high-speed internet access, switching built into some routers, and Voice-over-IP.
A problem with Linksys routers could make it possible for a remote user to gain sensitive information from a Linksys router. The problem is in the use of a default community string.
Linksys routers include a default community string of "public." By accessing a system using this string, a remote user may be able to gain sensitive information about a network managed by a vulnerable Linksys router.
Exploit / POC
Linksys DSL Router Default SNMP Community String Vulnerability
This vulnerability may be exploited by one of several available SNMP query tools.
This vulnerability may be exploited by one of several available SNMP query tools.
Solution / Fix
Linksys DSL Router Default SNMP Community String Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linksys DSL Router Default SNMP Community String Vulnerability
References:
References: