Linksys client-supplied XML data could be used to gain administrative access
| linksys-xml-admin-access (10651) |
Description:
Linksys EtherFast BEFSR41, BEFSR11, BEFSRU31, BEFW11S4, BEFVP41, BEFSX41, BEFSR81, BEFN2PS4, and HPRO200 routers could allow a remote attacker to gain unauthorized administrative access to the device without supplying a password. If the Web management interface has been enabled, a remote attacker could connect to the device on port 8080 and supply malicious XML data to cause the management setup screen to display. An attacker could use this vulnerability to view and modify sensitive router configuration information.
Consequences:
Bypass Security
Remedy:
Upgrade to the latest firmware version (1.43.3 or later), available from the Linksys Support Web page. See References.
References:
- BugTraq Mailing List, 2002-11-18 22:00:14: Linksys router vulnerability.
- BugTraq Mailing List, Mon Dec 02 2002 - 19:49:03 CST : CORE-20021005: Vulnerability Report For Linksys Devices .
- BugTraq Mailing List, Wed Nov 20 2002 - 14:37:48 CST: UPDATE: Linksys router vulnerability (add'l models affected).
- Core Security Technologies Advisory CORE-20021005: Vulnerability Report For Linksys Devices.
- Linksys Support Web site: Linksys: Firmware Upgrades.
- BID-6201: Linksys Router Unauthorized Management Access Vulnerability
Platforms Affected:
- Linksys BEFSR11 1.41
- Linksys BEFSR11 1.42.3
- Linksys BEFSR11 1.42.7
- Linksys BEFSR11 1.43
- Linksys BEFSR41 1.41
- Linksys BEFSR41 1.42.3
- Linksys BEFSR41 1.42.7
- Linksys BEFSR41 1.43
- Linksys BEFSRU31 1.41
- Linksys BEFSRU31 1.42.3
- Linksys BEFSRU31 1.42.7
- Linksys BEFSRU31 1.43
- Linksys BEFW11S4 1.4.2.7
- Linksys BEFW11S4 1.4.3
Reported:
Nov 18, 2002
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
