ID

VAR-190001-0079


TITLE

Linksys WAG54GS Wireless Router Cross-Site Request Forgery Vulnerability

Trust: 0.9

sources: CNVD: CNVD-2012-0815 // BID: 52105

DESCRIPTION

The Linksys WAG54GS Wireless Router is a wireless router device. A cross-site request forgery vulnerability exists in the Linksys WAG54GS Wireless Router. Because the program fails to properly validate user-submitted requests, an attacker can build a malicious URI, trick the user into parsing, and run privileged commands on the device, such as changing the configuration, performing a denial of service attack, or injecting arbitrary script code. Other attacks are also possible. Linksys WAG54GS running firmware 1.01.03 is vulnerable

Trust: 0.81

sources: CNVD: CNVD-2012-0815 // BID: 52105

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2012-0815

AFFECTED PRODUCTS

vendor:linksysmodel:wag54gsscope:eqversion:1.01.03

Trust: 0.9

sources: CNVD: CNVD-2012-0815 // BID: 52105

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201202-434

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201202-434

EXTERNAL IDS

db:BIDid:52105

Trust: 1.5

db:CNVDid:CNVD-2012-0815

Trust: 0.6

db:CNNVDid:CNNVD-201202-434

Trust: 0.6

sources: CNVD: CNVD-2012-0815 // BID: 52105 // CNNVD: CNNVD-201202-434

REFERENCES

url:http://www.securityfocus.com/bid/52105/

Trust: 0.6

url:http://www.securityfocus.com/bid/52105

Trust: 0.6

url:http://www.linksys.com/

Trust: 0.3

sources: CNVD: CNVD-2012-0815 // BID: 52105 // CNNVD: CNNVD-201202-434

CREDITS

Ivano Binetti

Trust: 0.9

sources: BID: 52105 // CNNVD: CNNVD-201202-434

SOURCES

db:CNVDid:CNVD-2012-0815
db:BIDid:52105
db:CNNVDid:CNNVD-201202-434

LAST UPDATE DATE

2022-05-17T02:02:15.981000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-0815date:2012-02-23T00:00:00
db:BIDid:52105date:2012-02-21T00:00:00
db:CNNVDid:CNNVD-201202-434date:2012-02-23T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2012-0815date:2012-02-23T00:00:00
db:BIDid:52105date:2012-02-21T00:00:00
db:CNNVDid:CNNVD-201202-434date:1900-01-01T00:00:00