821 : Linksys Router Default Password
Printer | http://osvdb.org/821 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
25 18316 over 9 years ago about 1 year ago 6 times 90%

Timeline

Discovery Date Disclosure Date
2002-09-12 2002-09-12

Description

By default, Linksys routers install with a default password. The administrative account has a password of admin which is publicly known and documented. This allows attackers to trivially access the program or system.

Classification

Location: Remote / Network Access, Local / Remote
Attack Type: Authentication Management
Impact: Loss of Integrity
Solution: Change Default Setting
Exploit: Exploit Public
Disclosure: Vendor Verified, Third-party Verified

Technical

1. Linksys - DSL
Method: Telnet
Password: admin
Level: Admin

2. Linksys - WAP Router
Version 4 Port, 2.4GHz
Method: HTTP
User ID: (blank)
Password: admin
Level: Administrator

3. Linksys - ADSL Router
Version 2700v
User ID: (none)
Password: epicrouter
Level: Administrator

4. Linksys - Wireless Router
Version WRT54G
User ID: (none)
Password: admin
Level: Administrator

5. Linksys - WET11
User ID: (none)
Password: admin
Level: Administrator

6. Linksys - WET54G
User ID: (none)
Password: admin
Level: Administrator

7. Linksys - WAP11
User ID: admin
Password: admin
Level: Administrator

8. Linksys - BEFW11S4
User ID: (none)
Password: admin
Level: Administrator

9. Linksys - WAG54G
User ID: admin
Password: admin
Level: Administrator

10. Linksys - WCG200
User ID: (none)
Password: admin
Level: Administrator

11. Linksys - SRW224
User ID: admin
Password: (blank)
Level: Administrator
Notes: Default management URL: http://192.168.1.254

12. Linksys - PSUS4
User ID: admin
Password: admin
Level: Administrator
Notes: Print Server for USB with 4-Port Switch

13. Linksys - WAP54G
User ID: (blank)
Password: admin
Level: Administrator
Notes: Default IP is 192.168.1.245

14. Linksys - WRT54GL
User ID: admin
Password: admin
Level: Administrator

Solution

Immediately after installation, change all default install passwords to a unique and secure password. When possible, change default accounts to custom names as well.

Products

Cisco Systems, Inc.
Watch-list
Linksys Routers
Watch-list
All

References

Tools & Filters

11522
1568

Snort

1860 1861

Credit

Unknown or Incomplete

CVSSv2 Score

We currently have no CVSS2 data on this vulnerability. Feel free to suggest it.

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

None found at this time

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use