CVE-2002-2159: Critical severity LinkSys BEFSR11 vulnerability
Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options are disabled, which allows remote attackers to gain access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In the router web administration interface, verify that the 'Remote Admin' setting is set to disabled.
Linksys BEFSR11 / BEFSR41 / BEFSRU31 (firmware 1.42.7) Remote Admin = disabled - Configuration
In the router web administration interface, verify that the 'Block WAN' setting is set to enabled.
Linksys BEFSR11 / BEFSR41 / BEFSRU31 (firmware 1.42.7) Block WAN = enabled - Compensating control
Block inbound TCP port 5678 at the network perimeter (firewall/ACL) or via upstream network controls for networks containing affected Linksys BEFSR11, BEFSR41, and BEFSRU31 devices to prevent remote administration access.
- Operational
Inventory Linksys BEFSR11, BEFSR41, and BEFSRU31 devices and identify any units with firmware version 1.42.7 installed.
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2159?
CVE-2002-2159 is considered to have a medium severity due to the potential for unauthorized remote access.
How do I fix CVE-2002-2159?
To fix CVE-2002-2159, upgrade the firmware of the affected Linksys models to a version that does not have this vulnerability.
Which devices are affected by CVE-2002-2159?
The devices affected by CVE-2002-2159 include the Linksys EtherFast Cable/DSL BEFSR11, BEFSR41, and BEFSRU31 running firmware version 1.42.7.
What is the risk associated with CVE-2002-2159?
The risk associated with CVE-2002-2159 is that remote attackers can gain access to the device due to an open TCP port 5678.
Is it possible to disable the remote administration feature on affected devices with CVE-2002-2159?
Yes, although the remote administration feature can be disabled, CVE-2002-2159 allows access despite these settings.