Title: Linksys Router Unauthorized Management Access Vulnerability
Severity: HIGH
Description:
Linksys DSL routers are high-speed internet access solutions distributed by the Linksys Group. Linksys DSL routers offer features such as high-speed internet access, switching built into some routers, and Voice-over-IP.
A vulnerability has been reported in various Linksys routers, during the initial negotiation stage. It has been reported that the vulnerable routers fail to handle XML-related data transmitted by clients during initialization of a session with the management server (on TCP port 8080 of the internal interface).
Reportedly, the authentication mechanism can be bypassed by requesting a .XML page. This feature is required for UPnP (Universal Plug and Play) functionality but is not disabled when UPnP support is disabled. The device allows access to /rootDesc.xml, /Layer3Forwarding.xml, /WANCfg.xml and WANIPCn.xml without authentication but, due to a flaw in the parser, any .XML request will allow access without authentication.
An attacker can exploit this vulnerability by using a browser to connect to the management interface and making a request for any .XML page. This will allow the attacker to bypass any authentication and access the device's management interface.
It should be noted that this issue must be exploited within an internal network, unless the remote management feature is enabled on the router.
It has also been reported that firmware revision 1.43.3 only partially fixes this vulnerability.
Affected Products:
- Linksys BEFW11S4 1.4.2.7
- Linksys BEFW11S4 1.4.3
- Linksys EtherFast BEFSR11 Router 1.41.0
- Linksys EtherFast BEFSR11 Router 1.42.3
- Linksys EtherFast BEFSR11 Router 1.42.7
- Linksys EtherFast BEFSR11 Router 1.43.0
- Linksys EtherFast BEFSR41 Router 1.41.0
- Linksys EtherFast BEFSR41 Router 1.42.3
- Linksys EtherFast BEFSR41 Router 1.42.7
- Linksys EtherFast BEFSR41 Router 1.43.0
- Linksys EtherFast BEFSRU31 Router 1.41.0
- Linksys EtherFast BEFSRU31 Router 1.42.3
- Linksys EtherFast BEFSRU31 Router 1.42.7
- Linksys EtherFast BEFSRU31 Router 1.43.0
References:
- Linksys: Driver Downloads
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.