CVE-2008-2636

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/06/2008
Last modified:
09/04/2025

Description

The HTTP service on the Cisco Linksys WRH54G with firmware 1.01.03 allows remote attackers to cause a denial of service (management interface outage) or possibly execute arbitrary code via a URI that begins with a "/./" sequence, contains many instances of a "front_page" sequence, and ends with a ".asp" sequence.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:linksys_wrh54g_router:1.01.03:*:*:*:*:*:*:*