PT-2005-4418 · Dell · Dell Truemobile 2300 Wireless Broadband Router
Tnull
·
Published
2005-12-08
·
Updated
2017-07-11
·
CVE-2005-3661
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Dell TrueMobile 2300 Wireless Broadband Router versions 3.0.0.8 through 5.1.1.6
Description
The issue allows remote attackers to reset authentication credentials and then change configuration or firmware by making a direct request to the "apply.cgi" endpoint with the
Page parameter set to adv password.asp.Recommendations
For versions 3.0.0.8 through 5.1.1.6, as a temporary workaround, consider restricting access to the "apply.cgi" endpoint to minimize the risk of exploitation. Avoid using the
Page parameter in the affected endpoint until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Truemobile 2300 Wireless Broadband Router