Lucene search

K
nvd[email protected]NVD:CVE-2005-2916
HistorySep 14, 2005 - 9:03 p.m.

CVE-2005-2916

2005-09-1421:03:00
web.nvd.nist.gov
3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

64.7%

Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.

Affected configurations

Nvd
Node
linksyswrt54gMatch3.01.3
OR
linksyswrt54gMatch3.03.6
OR
linksyswrt54gMatch4.00.7
VendorProductVersionCPE
linksyswrt54g3.01.3cpe:2.3:h:linksys:wrt54g:3.01.3:*:*:*:*:*:*:*
linksyswrt54g3.03.6cpe:2.3:h:linksys:wrt54g:3.03.6:*:*:*:*:*:*:*
linksyswrt54g4.00.7cpe:2.3:h:linksys:wrt54g:4.00.7:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

64.7%

Related for NVD:CVE-2005-2916