CVE-2010-1573
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 20.79% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- linksys/wap54g firmware
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/40103Broken Link
- http://tools.cisco.com/security/center/viewAlert.x?alertId=20682Broken Link, Vendor Advisory
- http://www.icysilence.org/?p=268Exploit
- http://www.securityfocus.com/archive/1/511733/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/40648Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1419Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59286Third Party Advisory, VDB Entry
- http://secunia.com/advisories/40103Broken Link
- http://tools.cisco.com/security/center/viewAlert.x?alertId=20682Broken Link, Vendor Advisory
- http://www.icysilence.org/?p=268Exploit
- http://www.securityfocus.com/archive/1/511733/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/40648Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1419Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59286Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.