CVE-2006-5202
Description
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
Is your site exposed to CVE-2006-5202?
Run a free security scan — no signup, results in seconds.
Affected Products
| Vendor | Product |
|---|---|
| linksys | wrt54g |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2006-5202? +
What products are affected by CVE-2006-5202? +
How do I check if I'm vulnerable to CVE-2006-5202? +
Related Vulnerabilities
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows …
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access …
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.