Linksys routers contain a flaw that may allow a malicious user to access the Remote Administration interface. The issue is triggered by the interface being available on port 443, even when Remote Administration is disabled. It is possible that the flaw may allow unauthorized administrative access resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Authentication Management,
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Upgrade to version 2.02.8 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: Enable the integrated firewall.