HTTP: Linksys WVC54GC ActiveX Control

This signature detects access to a vulnerable ActiveX control for managing Linksys WVC54GC devices. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX components, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Linksys WVC54GC NetCamPlayerWeb11gv2 Agent ActiveX Control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input. An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions. WVC53GC with firmware versions prior to 1.25 that include the ActiveX control are vulnerable.

Affected Products

Linksys wvc54gc

References

BugTraq: 32665

CVE: CVE-2008-4391

Short Name
HTTP:STC:ACTIVEX:LINKSYS
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
ActiveX CVE-2008-4391 Control Linksys WVC54GC bid:32665
Release Date
12/10/2008
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Linksys

CVSS Score

9.3

Found a potential security threat?