Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1244
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1244

Description:
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41124

SAID
  Secunia Advisory: SA29345

MISC
  http://www.gnucitizen.org/projects/router-hacking-challenge/

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/489009/100/0/threaded

BID
  28319


Return to the previous page.