CVE-2002-1236: Medium severity LinkSys BEFSR41 vulnerability
Published Nov 12, 2002
·Updated
The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.
Affected Software
4 affected components
LinkSys BEFSR41=1.40.2
LinkSys BEFSR41=1.42.3
LinkSys BEFSR41=1.42.7
LinkSys BEFSR41=1.41
Remediation
Patch Available
Event History
Nov 12, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1236?
The severity of CVE-2002-1236 is classified as high due to its potential for remote denial of service attacks.
2
How do I fix CVE-2002-1236?
To fix CVE-2002-1236, update the Linksys BEFSR41 firmware to version 1.42.7 or later.
3
What devices are affected by CVE-2002-1236?
CVE-2002-1236 affects the Linksys BEFSR41 EtherFast Cable/DSL Router with firmware versions prior to 1.42.7.
4
What type of attack does CVE-2002-1236 allow?
CVE-2002-1236 allows attackers to launch a denial of service attack that may crash the router.
5
Is CVE-2002-1236 a specific attack vector?
Yes, CVE-2002-1236 specifically uses an HTTP request to the Gozila.cgi script without any arguments as the attack vector.