CVE-2013-3066: High severity LinkSys Ea6500 Firmware vulnerability
Published Sep 29, 2014
·Updated
Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients and router configuration) via a request to /JNAP/.
Affected Software
2 affected components
LinkSys Ea6500 Firmware=1.1.28.147876
LinkSys EA6500
Event History
Sep 29, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3066?
CVE-2013-3066 is a high severity vulnerability that allows remote attackers to obtain sensitive information from Linksys EA6500 routers.
2
Who is affected by CVE-2013-3066?
CVE-2013-3066 affects Linksys EA6500 routers running firmware version 1.1.28.147876.
3
How do I fix CVE-2013-3066?
To fix CVE-2013-3066, update the Linksys EA6500 firmware to the latest version that addresses this vulnerability.
4
What information can be leaked due to CVE-2013-3066?
CVE-2013-3066 allows attackers to access sensitive information including clients and router configurations.
5
Can CVE-2013-3066 be exploited remotely?
Yes, CVE-2013-3066 can be exploited remotely without authentication by attackers.