CyberSec.Space Logo
返回 CVE 浏览器

CVE-2008-1247

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1490%
EPSS Percentile19.38th
Published2008年3月10日
Last Modified2026年4月23日

Vulnerability Description

The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers to perform arbitrary administrative actions via a direct request to (1) Advanced.tri, (2) AdvRoute.tri, (3) Basic.tri, (4) ctlog.tri, (5) ddns.tri, (6) dmz.tri, (7) factdefa.tri, (8) filter.tri, (9) fw.tri, (10) manage.tri, (11) ping.tri, (12) PortRange.tri, (13) ptrigger.tri, (14) qos.tri, (15) rstatus.tri, (16) tracert.tri, (17) vpn.tri, (18) WanMac.tri, (19) WBasic.tri, or (20) WFilter.tri. NOTE: the Security.tri vector is already covered by CVE-2006-5202.

Affected Platforms (CPE)

🔌
Linksys

Wrt54g

All versions

References & Advisories

相关漏洞威胁