peter bassill · operator
$ cve CVE-2008-1247 JSON

CVE-2008-1247 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers to perform arbitrary administrative actions via a direct request to (1) Advanced.tri, (2) AdvRoute.tri, (3) Basic.tri, (4) ctlog.tri, (5) ddns.tri, (6) dmz.tri, (7) factdefa.tri, (8) filter.tri, (9) fw.tri, (10) manage.tri, (11) ping.tri, (12) PortRange.tri, (13) ptrigger.tri, (14) qos.tri, (15) rstatus.tri, (16) tracert.tri, (17) vpn.tri, (18) WanMac.tri, (19) WBasic.tri, or (20) WFilter.tri. NOTE: the Security.tri vector is already covered by CVE-2006-5202.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS5.16% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2008-03-10
Last modified2026-06-16

Affected (1)

VendorProduct
linksyswrt54g

Public exploits

SourceTitleDate
exploit-dbLinksys WRT54G Firmware 1.00.9 - Security Bypass (1)2008-03-26

References

→ the Explorer  ·  watch your stack  ·  NVD