ID

VAR-200803-0168


CVE

CVE-2008-1245


TITLE

Belkin F5D7230-4 On the router cgi-bin/setup_virtualserver.exe Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2008-002823

DESCRIPTION

cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connection: Keep-Alive" header. The Belkin F5D7230-4 Wireless G Router is prone to a denial-of-service vulnerability. Attackers can exploit this issue to deny access to the device's control center for legitimate users. Belkin F5D7230-4 running firmware 9.01.10 is vulnerable; other devices and firmware versions may also be affected. ---------------------------------------------------------------------- A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI has been released. The new version includes many new and advanced features, which makes it even easier to stay patched. Download and test it today: https://psi.secunia.com/ Read more about this new version: https://psi.secunia.com/?page=changelog ---------------------------------------------------------------------- TITLE: Belkin Wireless G Router Security Bypass and Denial of Service SECUNIA ADVISORY ID: SA29345 VERIFY ADVISORY: http://secunia.com/advisories/29345/ CRITICAL: Less critical IMPACT: Security Bypass, DoS WHERE: >From local network OPERATING SYSTEM: Belkin Wireless G Router http://secunia.com/product/6130/ DESCRIPTION: Some security issues and a vulnerability have been reported in the Belkin Wireless G Router, which can be exploited by malicious people to bypass certain security restrictions or cause a DoS (Denial of Service). 1) An error in the implementation of authenticated sessions can be exploited to gain access to the router's control panel by establishing a session from a previously authenticated IP address. 2) An error exists within the enforcing of permissions in cgi-bin/setup_dns.exe. This can be exploited to perform restricted administrative actions by directly accessing the vulnerable script. 3) An error exists in the cgi-bin/setup_virtualserver.exe script when processing HTTP POST data. The security issues and the vulnerability are reported in model F5D7230-4, firmware version 9.01.10. SOLUTION: Restrict network access to the router's web interface. PROVIDED AND/OR DISCOVERED BY: loftgaia ORIGINAL ADVISORY: http://www.gnucitizen.org/projects/router-hacking-challenge/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.16

sources: NVD: CVE-2008-1245 // JVNDB: JVNDB-2008-002823 // BID: 28322 // VULHUB: VHN-31370 // PACKETSTORM: 69581 // PACKETSTORM: 64737

AFFECTED PRODUCTS

vendor:belkinmodel:f5d7230-4scope:eqversion:*

Trust: 1.0

vendor:belkinmodel:f5d7230-4scope:eqversion:firmware 9.01.10

Trust: 0.8

vendor:belkinmodel:f5d7230-4scope:eqversion:9.01.10

Trust: 0.6

vendor:belkinmodel:f5d7230-4 wireless g routerscope:eqversion:9.1.10

Trust: 0.3

sources: BID: 28322 // JVNDB: JVNDB-2008-002823 // CNNVD: CNNVD-200803-123 // NVD: CVE-2008-1245

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-1245
value: HIGH

Trust: 1.0

NVD: CVE-2008-1245
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200803-123
value: HIGH

Trust: 0.6

VULHUB: VHN-31370
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2008-1245
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-31370
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-31370 // JVNDB: JVNDB-2008-002823 // CNNVD: CNNVD-200803-123 // NVD: CVE-2008-1245

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-31370 // JVNDB: JVNDB-2008-002823 // NVD: CVE-2008-1245

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200803-123

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200803-123

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-002823

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-31370

PATCH

title:Top Pageurl:http://www.belkin.com/

Trust: 0.8

sources: JVNDB: JVNDB-2008-002823

EXTERNAL IDS

db:NVDid:CVE-2008-1245

Trust: 2.8

db:BIDid:28322

Trust: 2.0

db:SECUNIAid:29345

Trust: 1.8

db:JVNDBid:JVNDB-2008-002823

Trust: 0.8

db:CNNVDid:CNNVD-200803-123

Trust: 0.7

db:BUGTRAQid:20080301 THE ROUTER HACKING CHALLENGE IS OVER!

Trust: 0.6

db:XFid:41116

Trust: 0.6

db:XFid:5

Trust: 0.6

db:EXPLOIT-DBid:6305

Trust: 0.2

db:SECUNIAid:31665

Trust: 0.2

db:VULHUBid:VHN-31370

Trust: 0.1

db:PACKETSTORMid:69581

Trust: 0.1

db:PACKETSTORMid:64737

Trust: 0.1

sources: VULHUB: VHN-31370 // BID: 28322 // JVNDB: JVNDB-2008-002823 // PACKETSTORM: 69581 // PACKETSTORM: 64737 // CNNVD: CNNVD-200803-123 // NVD: CVE-2008-1245

REFERENCES

url:http://www.gnucitizen.org/projects/router-hacking-challenge/

Trust: 1.8

url:http://www.securityfocus.com/bid/28322

Trust: 1.7

url:http://secunia.com/advisories/29345

Trust: 1.7

url:http://www.securityfocus.com/archive/1/489009/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/41116

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-1245

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-1245

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/489009/100/0/threaded

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/41116

Trust: 0.6

url:http://catalog.belkin.com/iwcatproductpage.process?merchant_id=&section_id=201522&pcount=&product_id=136493

Trust: 0.3

url:/archive/1/489009

Trust: 0.3

url:http://secunia.com/product/6130/

Trust: 0.2

url:http://secunia.com/secunia_security_advisories/

Trust: 0.2

url:http://secunia.com/advisories/29345/

Trust: 0.2

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.2

url:http://secunia.com/about_secunia_advisories/

Trust: 0.2

url:http://secunia.com/advisories/31665/

Trust: 0.1

url:http://milw0rm.com/exploits/6305

Trust: 0.1

url:http://secunia.com/hardcore_disassembler_and_reverse_engineer/

Trust: 0.1

url:http://secunia.com/secunia_security_specialist/

Trust: 0.1

url:https://psi.secunia.com/?page=changelog

Trust: 0.1

url:https://psi.secunia.com/

Trust: 0.1

sources: VULHUB: VHN-31370 // BID: 28322 // JVNDB: JVNDB-2008-002823 // PACKETSTORM: 69581 // PACKETSTORM: 64737 // CNNVD: CNNVD-200803-123 // NVD: CVE-2008-1245

CREDITS

pdp pdp.gnucitizen@googlemail.com

Trust: 0.6

sources: CNNVD: CNNVD-200803-123

SOURCES

db:VULHUBid:VHN-31370
db:BIDid:28322
db:JVNDBid:JVNDB-2008-002823
db:PACKETSTORMid:69581
db:PACKETSTORMid:64737
db:CNNVDid:CNNVD-200803-123
db:NVDid:CVE-2008-1245

LAST UPDATE DATE

2025-04-10T20:45:47.069000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-31370date:2018-10-11T00:00:00
db:BIDid:28322date:2008-03-19T18:20:00
db:JVNDBid:JVNDB-2008-002823date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200803-123date:2008-09-05T00:00:00
db:NVDid:CVE-2008-1245date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-31370date:2008-03-10T00:00:00
db:BIDid:28322date:2008-03-01T00:00:00
db:JVNDBid:JVNDB-2008-002823date:2012-06-26T00:00:00
db:PACKETSTORMid:69581date:2008-09-03T19:29:48
db:PACKETSTORMid:64737date:2008-03-20T00:11:50
db:CNNVDid:CNNVD-200803-123date:2008-03-10T00:00:00
db:NVDid:CVE-2008-1245date:2008-03-10T17:44:00