Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
2006-05-24T01:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Hardware | linksys | wrt54g | 1.42.3 | Yes |
Hardware | linksys | wrt54g | 2.00.8 | Yes |
Hardware | linksys | wrt54g | 2.02.7 | Yes |
Hardware | linksys | wrt54g | 2.04.4 | Yes |
Hardware | linksys | wrt54g | 2.04.4_non_default | Yes |
Hardware | linksys | wrt54g | 3.01.3 | Yes |
Hardware | linksys | wrt54g | 3.03.6 | Yes |
Hardware | linksys | wrt54g | 4.00.7 | Yes |
Hardware | linksys | wrt54g_v5 | * | Yes |