Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wrt54g | Linksys | 1.42.3 (including) | 1.42.3 (including) |
Wrt54g | Linksys | 2.00.8 (including) | 2.00.8 (including) |
Wrt54g | Linksys | 2.02.7 (including) | 2.02.7 (including) |
Wrt54g | Linksys | 2.04.4 (including) | 2.04.4 (including) |
Wrt54g | Linksys | 2.04.4_non_default (including) | 2.04.4_non_default (including) |
Wrt54g | Linksys | 3.01.3 (including) | 3.01.3 (including) |
Wrt54g | Linksys | 3.03.6 (including) | 3.03.6 (including) |
Wrt54g | Linksys | 4.00.7 (including) | 4.00.7 (including) |
Wrt54g_v5 | Linksys | * | * |