CVE-2006-3561
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1)…
Does this matter?
Lower severity and a low EPSS score (6.72%). Track it; it rarely justifies an emergency change on its own.
Description
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1) /btvoyager_getconfig.sh, PPP credentials via (2) btvoyager_getpppcreds.sh, and decode configuration credentials via (3) btvoyager_decoder.c.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 6.72% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-264
- Affected
- bt/voyager 2091 wireless adsl router
- Source
- cve@mitre.org
References
- http://ikwt.dyndns.org/projects/btvoyager-getconfig.txtExploit
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047733.html
- http://secunia.com/advisories/20982Vendor Advisory
- http://www.gnucitizen.org/blog/holes-in-embedded-devices-authentication-bypass-pt-3/
- http://www.gnucitizen.org/projects/router-hacking-challenge/
- http://www.securityfocus.com/archive/1/440405/100/0/threaded
- http://www.securityfocus.com/archive/1/489009/100/0/threaded
- http://www.securityfocus.com/bid/19057
- http://www.vupen.com/english/advisories/2006/2734
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27652
- http://ikwt.dyndns.org/projects/btvoyager-getconfig.txtExploit
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047733.html
- http://secunia.com/advisories/20982Vendor Advisory
- http://www.gnucitizen.org/blog/holes-in-embedded-devices-authentication-bypass-pt-3/
- http://www.gnucitizen.org/projects/router-hacking-challenge/
- http://www.securityfocus.com/archive/1/440405/100/0/threaded
- http://www.securityfocus.com/archive/1/489009/100/0/threaded
- http://www.securityfocus.com/bid/19057
- http://www.vupen.com/english/advisories/2006/2734
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27652
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.