First published: Tue Nov 12 2002(Updated: )
The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys BEFSR41 | =1.40.2 | |
Linksys BEFSR41 | =1.42.3 | |
Linksys BEFSR41 | =1.42.7 | |
Linksys BEFSR41 | =1.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-1236 is classified as high due to its potential for remote denial of service attacks.
To fix CVE-2002-1236, update the Linksys BEFSR41 firmware to version 1.42.7 or later.
CVE-2002-1236 affects the Linksys BEFSR41 EtherFast Cable/DSL Router with firmware versions prior to 1.42.7.
CVE-2002-1236 allows attackers to launch a denial of service attack that may crash the router.
Yes, CVE-2002-1236 specifically uses an HTTP request to the Gozila.cgi script without any arguments as the attack vector.