CVE-2013-3066

Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients and router configuration) via a request to /JNAP/.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:linksys:ea6500_firmware:1.1.28.147876:*:*:*:*:*:*:*
cpe:2.3:h:linksys:ea6500:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:52

Type Values Removed Values Added
References () http://securityevaluators.com/knowledge/case_studies/routers/Vulnerability_Catalog.pdf - Exploit () http://securityevaluators.com/knowledge/case_studies/routers/Vulnerability_Catalog.pdf - Exploit
References () http://securityevaluators.com/knowledge/case_studies/routers/linksys_ea6500.php - Exploit () http://securityevaluators.com/knowledge/case_studies/routers/linksys_ea6500.php - Exploit

Information

Published : 2014-09-29 22:55

Updated : 2024-11-21 01:52


NVD link : CVE-2013-3066

Mitre link : CVE-2013-3066

CVE.ORG link : CVE-2013-3066


JSON object : View

Products Affected

linksys

  • ea6500_firmware
  • ea6500
CWE
CWE-264

Permissions, Privileges, and Access Controls