vendor:
Linksys routers
by:
Unknown
5.5
CVSS
MEDIUM
CSRF
352
CWE
Product Name: Linksys routers
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
CSRF vulnerabilities in Linksys routers
There are multiple unpatched CSRF vulnerabilities in the administration interfaces for various Linksys routers. Exploits are available that allow remote administration of the router and changing the password to '__pwn3d__'. The victim does not necessarily need to be authenticated since the default passwords for all routers are known to be 'admin'. Most browsers provide some degree of protection against these attacks.
Mitigation:
Avoid surfing the web while authenticated in the router's administration interface. Change the default password.