Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2916

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2005-2916
Last Modified 05 Sep 2008 04:52:59
Published 14 Sep 2005 05:03:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-2916

Summary

Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.

Vulnerable Systems


References

IDEFENSE - 20050913 Linksys WRT54G 'upgrade.cgi' Firmware Upload Design Error Vulnerability

IDEFENSE - 20050913 Linksys WRT54G 'restore.cgi' Configuration Modification Design Error Vulnerability


Last Updated: 27 May 2016 10:40:40