ID

VAR-201006-0503


TITLE

Linksys WAP54Gv3 Wireless Router Debug Credential Security Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2010-1073

DESCRIPTION

Linksys WAP54G is a wireless router device. The Linksys WAP54G debug interface allows the SHELL command to execute any root privileges through the WEB page of the device, and the embedded credentials cannot be changed by the user. The WEB page of the following URL allows the shell command to be executed on the device: http://AP_IP_ADDR/Debug_command_page.asphttp://AP_IP_ADDR/debug.cgi where AP_IP_ADDR is the IP address of the device and provides the following authentication information: User: GemtekPassword: gemtekswd Access the device and execute shell commands with root privileges. Smart Statistics is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. Smart Statistics 1.0 is vulnerable; other versions may also be affected

Trust: 0.81

sources: CNVD: CNVD-2010-1073 // BID: 40468

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-1073

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:sentosoftmodel:smart statisticsscope:eqversion:1.0

Trust: 0.3

sources: CNVD: CNVD-2010-1073 // BID: 40468

THREAT TYPE

network

Trust: 0.3

sources: BID: 40468

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 40468

EXTERNAL IDS

db:BIDid:40468

Trust: 0.9

db:CNVDid:CNVD-2010-1073

Trust: 0.6

sources: CNVD: CNVD-2010-1073 // BID: 40468

REFERENCES

url:http://www.icysilence.org/?p=268

Trust: 0.6

url:http://www.sentosoft.com/

Trust: 0.3

url:http://www.smartphpstatistics.com/

Trust: 0.3

sources: CNVD: CNVD-2010-1073 // BID: 40468

CREDITS

R3d-D3v!L

Trust: 0.3

sources: BID: 40468

SOURCES

db:CNVDid:CNVD-2010-1073
db:BIDid:40468

LAST UPDATE DATE

2022-05-17T01:48:46.987000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1073date:2010-06-10T00:00:00
db:BIDid:40468date:2010-01-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-1073date:2010-06-10T00:00:00
db:BIDid:40468date:2010-01-10T00:00:00