CVE-2006-2559: High severity LinkSys WRT54G vulnerability
Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2559?
CVE-2006-2559 is considered to be of medium severity due to its ability to allow unauthorized access and operations.
How do I fix CVE-2006-2559?
To fix CVE-2006-2559, disable UPnP on the Linksys WRT54G router's settings.
Which versions of Linksys WRT54G are affected by CVE-2006-2559?
CVE-2006-2559 affects several versions of Linksys WRT54G, including 1.42.3, 2.00.8, 2.02.7, 2.04.4, 3.01.3, 3.03.6, and 4.00.7.
Can CVE-2006-2559 be exploited remotely?
Yes, CVE-2006-2559 can be exploited remotely using a specially crafted UPnP request.
What types of unauthorized operations can CVE-2006-2559 allow?
CVE-2006-2559 can allow attackers to forward arbitrary traffic by manipulating the InternalClient parameter in UPnP requests.