PT-2002-2855 · Eusso+4 · Eusso Gl2422-Ap+4

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2137

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GlobalSunTech Wireless Access Points version not specified D-Link DWL-900AP+ versions 2.1 and 2.2 ALLOY GL-2422AP-S version not specified EUSSO GL2422-AP version not specified LINKSYS WAP11-V2.2 version not specified
Description: The issue allows remote attackers to obtain sensitive information, including WEP keys, the administrator password, and the MAC filter, by sending a "getsearch" request to UDP port 27155.
Recommendations: For GlobalSunTech Wireless Access Points, restrict access to UDP port 27155 until a fix is available. For D-Link DWL-900AP+, avoid using versions 2.1 and 2.2 until a patch is released. For ALLOY GL-2422AP-S, EUSSO GL2422-AP, and LINKSYS WAP11-V2.2, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2137

Affected Products

Alloy Gl-2422Ap-S
D-Link Dwl-900Ap+
Eusso Gl2422-Ap
Globalsuntech Wireless Access Points
Linksys Wap11-V2.2