CVE-2006-5202: Medium severity linksys wrt54g vulnerability
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5202?
CVE-2006-5202 has a high severity due to the lack of authentication allowing remote configuration changes.
How do I fix CVE-2006-5202?
To fix CVE-2006-5202, upgrade the firmware of the Linksys WRT54G to a version that requires authentication for configuration changes.
What devices are affected by CVE-2006-5202?
CVE-2006-5202 specifically affects the Linksys WRT54G router running firmware version 1.00.9.
What attack vectors are associated with CVE-2006-5202?
CVE-2006-5202 allows attackers to make arbitrary configuration changes via direct HTTP requests without authentication.
When was CVE-2006-5202 reported?
CVE-2006-5202 was reported in 2006, highlighting a significant security flaw in the Linksys WRT54G firmware.