The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:53
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.linksys.com/pub/network/wrt54g_2.02.8_US_code_beta.zip - Patch | |
References | () http://archives.neohapsis.com/archives/bugtraq/2004-05/0316.html - | |
References | () http://archives.neohapsis.com/archives/bugtraq/2004-06/0002.html - | |
References | () http://archives.neohapsis.com/archives/bugtraq/2004-06/0020.html - | |
References | () http://archives.neohapsis.com/archives/bugtraq/2004-06/0190.html - | |
References | () http://secunia.com/advisories/11754 - Patch, Vendor Advisory | |
References | () http://web.archive.org/web/20040823075750/http://www.linksys.com/download/firmware.asp?fwid=201 - Patch | |
References | () http://www.nwfusion.com/news/2004/0607confuse.html - | |
References | () http://www.osvdb.org/6577 - | |
References | () http://www.securityfocus.com/archive/1/365175 - | |
References | () http://www.securityfocus.com/archive/1/365227/30/0/threaded - | |
References | () http://www.securityfocus.com/bid/10441 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16274 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:53
NVD link : CVE-2004-2606
Mitre link : CVE-2004-2606
CVE.ORG link : CVE-2004-2606
JSON object : View
Products Affected
linksys
- befsr41_v3
- wrt54g
CWE