CVE-2004-0641 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.61% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-08-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| thomson | speedtouch |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Linux Kernel 2.2 - Predictable TCP Initial Sequence Number | 1999-09-27 |
References
- http://secunia.com/advisories/12238/
- http://www.auscert.org.au/render.html?it=4299
- http://www.idefense.com/application/poi/display?id=120&type=vulnerabilities&flashstatus=true
- http://www.securityfocus.com/bid/10881
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16919
- http://secunia.com/advisories/12238/
- http://www.auscert.org.au/render.html?it=4299
- http://www.idefense.com/application/poi/display?id=120&type=vulnerabilities&flashstatus=true
- http://www.securityfocus.com/bid/10881
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16919
→ the Explorer · watch your stack · NVD