ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authentication initialization function, which allows remote attackers to obtain encrypted configuration information and, if the key is known, modify the configuration.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-09-14T04:00:00Z
Updated: 2024-09-16T22:56:41.082Z
Reserved: 2005-09-14T00:00:00Z
Link: CVE-2005-2914
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-09-14T21:03:00.000
Modified: 2024-11-21T00:00:42.640
Link: CVE-2005-2914
Redhat
No data.