First published: Mon Mar 10 2008(Updated: )
The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a file that lists all HTML documents, and an ELF executable file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys WRT54G |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-1264 is considered high due to the ease with which remote attackers can exploit the default FTP password.
To fix CVE-2008-1264, change the default FTP password from 'admin' to a strong, unique password.
Attackers can access sensitive files including nvram.cfg, which contains configuration data and sensitive information.
CVE-2008-1264 specifically affects the Linksys WRT54G router models.
Yes, CVE-2008-1264 remains a concern for devices that have not been updated or have not had their default passwords changed.