vendor:
WAG54GS
by:
Ivano Binetti
7,8
CVSS
HIGH
CSRF
352
CWE
Product Name: WAG54GS
Affected Version From: V1.01.03
Affected Version To: V1.01.03
Patch Exists: NO
Related CWE: N/A
CPE: h:linksys:wag54gs
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Cisco Linksys WAG54GS (ADSL Router) change admin password
The web interface of this router is prone to CSRF vulnerabilities which allows to change router parameters and - among other things - to change default administrator ("admin") password.
Mitigation:
Implementing CSRF protection mechanisms, such as random tokens, can help mitigate the risk of CSRF attacks.