Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown

CVE-2006-5202

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
0
Attacker Value
Unknown

CVE-2006-2559

Disclosure Date: May 24, 2006 (last updated October 04, 2023)
Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
0
Attacker Value
Unknown

CVE-2006-1067

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single long argument, or (2) a DCC SEND with IP, port, and filesize arguments with a 0 value.
0
Attacker Value
Unknown

CVE-2005-4257

Disclosure Date: December 15, 2005 (last updated February 22, 2025)
Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
0
Attacker Value
Unknown

CVE-2005-2799

Disclosure Date: September 15, 2005 (last updated February 22, 2025)
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.
0
Attacker Value
Unknown

CVE-2005-2915

Disclosure Date: September 14, 2005 (last updated February 22, 2025)
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration information, which could allow attackers to decrypt the information and possibly re-encrypt it in conjunction with CVE-2005-2914.
0
Attacker Value
Unknown

CVE-2005-2912

Disclosure Date: September 14, 2005 (last updated February 22, 2025)
Linksys WRT54G router allows remote attackers to cause a denial of service (CPU consumption and server hang) via an HTTP POST request with a negative Content-Length value.
0
Attacker Value
Unknown

CVE-2005-2916

Disclosure Date: September 14, 2005 (last updated February 22, 2025)
Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.
0
Attacker Value
Unknown

CVE-2005-2914

Disclosure Date: September 14, 2005 (last updated February 22, 2025)
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authentication initialization function, which allows remote attackers to obtain encrypted configuration information and, if the key is known, modify the configuration.
0
Attacker Value
Unknown

CVE-2005-2589

Disclosure Date: August 17, 2005 (last updated February 22, 2025)
Unknown vulnerability in Linksys WRT54GS wireless router with firmware 4.50.6, with WPA Personal/TKIP authentication enabled, allows remote clients to bypass authentication by connecting without using encryption.
0