First published: Mon Oct 09 2006(Updated: )
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Linksys WRT54G Router Firmware | =1.00.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5202 has a high severity due to the lack of authentication allowing remote configuration changes.
To fix CVE-2006-5202, upgrade the firmware of the Linksys WRT54G to a version that requires authentication for configuration changes.
CVE-2006-5202 specifically affects the Linksys WRT54G router running firmware version 1.00.9.
CVE-2006-5202 allows attackers to make arbitrary configuration changes via direct HTTP requests without authentication.
CVE-2006-5202 was reported in 2006, highlighting a significant security flaw in the Linksys WRT54G firmware.