CVE-2006-5202
Description
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
Is your site exposed to CVE-2006-5202?
Run a free security scan — no signup, results in seconds.
Affected Products
| Vendor | Product |
|---|---|
| linksys | wrt54g |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2006-5202? +
What products are affected by CVE-2006-5202? +
How do I check if I'm vulnerable to CVE-2006-5202? +
Related Vulnerabilities
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows …
In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access …
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the …
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.