Описание
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
Ссылки
- Exploit
- Vendor Advisory
- Exploit
- US Government Resource
- Exploit
- Exploit
- Vendor Advisory
- Exploit
- US Government Resource
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:h:linksys:wrt54g:1.00.9:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.28692
Средний
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
EPSS
Процентиль: 96%
0.28692
Средний
5 Medium
CVSS2
Дефекты
NVD-CWE-Other