CVE-2009-1561

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
06/05/2009
Last modified:
09/04/2025

Description

Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password via the sysPasswd and sysConfirmPasswd parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:wrt54gc:1.05.7:*:*:*:*:*:*:*