Cisco Linksys WRT160N Multiple Security Vulnerabilities
BID:57887
Info
Cisco Linksys WRT160N Multiple Security Vulnerabilities
| Bugtraq ID: | 57887 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2013 12:00AM |
| Updated: | May 21 2013 07:53AM |
| Credit: | Michael Messner |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Linksys WRT160N Multiple Security Vulnerabilities
Cisco Linksys WRT160N is prone to the following security vulnerabilities:
1. A remote command-execution vulnerability
2. A directory-traversal vulnerability
3. A cross-site request-forgery vulnerability
4. Multiple cross-site scripting vulnerabilities
5. Multiple security-bypass vulnerabilities
An attacker can exploit these issues to execute arbitrary commands, bypass certain security restrictions, steal cookie-based authentication credentials, view or download arbitrary files from the server, gain access to system and other configuration files, or perform unauthorized actions in the context of a user session.
Cisco Linksys WRT160N is prone to the following security vulnerabilities:
1. A remote command-execution vulnerability
2. A directory-traversal vulnerability
3. A cross-site request-forgery vulnerability
4. Multiple cross-site scripting vulnerabilities
5. Multiple security-bypass vulnerabilities
An attacker can exploit these issues to execute arbitrary commands, bypass certain security restrictions, steal cookie-based authentication credentials, view or download arbitrary files from the server, gain access to system and other configuration files, or perform unauthorized actions in the context of a user session.
Exploit / POC
Cisco Linksys WRT160N Multiple Security Vulnerabilities
An attacker can exploit these issues through a browser. To exploit cross-site scripting and cross-site request-forgery issues the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example data and exploit code are available:
An attacker can exploit these issues through a browser. To exploit cross-site scripting and cross-site request-forgery issues the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example data and exploit code are available:
Solution / Fix
Cisco Linksys WRT160N Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Linksys WRT160N Multiple Security Vulnerabilities
References:
References: