20090418 Linksys WRT54GC - Admin Password Change (POC)mailing list
http://archives.neohapsis.com/archives/bugtraq/2009-04/0198.html CVE-2009-1561
Linksys WRT54GC 1.5.7 Firmware - 'administration.cgi' Access Validation
Record summary
CVE-2009-1561 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password via the sysPasswd and sysConfirmPasswd parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLinksys WRT54GC 1.5.7 Firmware - 'administration.cgi' Access ValidationExploitDB exploitby Gabriel LimaNot analyzed1 file
References
7packetstormsecurity.org
http://packetstormsecurity.org/0904-exploits/linksysadmin-passwd.txt 34805Third-party advisory
http://secunia.com/advisories/34805 falandodeseguranca.com
http://www.falandodeseguranca.com/?p=17 34616vdb entry
http://www.securityfocus.com/bid/34616 ADV-2009-1172vdb entry
http://www.vupen.com/english/advisories/2009/1172 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-1561