First published: Fri Dec 31 2004(Updated: )
The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys BEFSR41 | ||
Cisco Linksys WRT54G Router Firmware | =2.02.7 |
http://web.archive.org/web/20040823075750/http://www.linksys.com/download/firmware.asp?fwid=201
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2606 has a low severity rating but poses a risk as it can allow unauthorized login attempts to the administration web page.
To mitigate CVE-2004-2606, ensure that remote administration features are disabled and apply the latest firmware updates from Linksys.
CVE-2004-2606 affects users of Linksys WRT54G version 2.02.7 and BEFSR41 version 3 with the firewall disabled.
The impact of CVE-2004-2606 is that remote attackers may exploit it to attempt unauthorized access to the router's admin interface.
Yes, CVE-2004-2606 can be exploited easily by remote attackers due to misconfigured settings on affected devices.