← Vulnerability feed

Vulnerability record · CVE-2004-2606 · published 31 December 2004

CVE-2004-2606: Linksys befsr41 v3 vulnerability

Linksys · Befsr41 V3

The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.

7.5 CVSS 2.0 High EPSS 2.6% · top 15.5%
7.5CVSS 2.0 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.linksys.com/pub/network/wrt54g_2.02.8_US_code_beta.zip Patch
http://archives.neohapsis.com/archives/bugtraq/2004-05/0316.html
http://archives.neohapsis.com/archives/bugtraq/2004-06/0002.html
http://archives.neohapsis.com/archives/bugtraq/2004-06/0020.html
http://archives.neohapsis.com/archives/bugtraq/2004-06/0190.html
http://secunia.com/advisories/11754 PatchVendor Advisory
http://web.archive.org/web/20040823075750/http://www.linksys.com/download/firmware.asp?fwid=201 Patch
http://www.nwfusion.com/news/2004/0607confuse.html
http://www.osvdb.org/6577
http://www.securityfocus.com/archive/1/365175
http://www.securityfocus.com/archive/1/365227/30/0/threaded
http://www.securityfocus.com/bid/10441 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/16274
ftp://ftp.linksys.com/pub/network/wrt54g_2.02.8_US_code_beta.zip Patch
http://archives.neohapsis.com/archives/bugtraq/2004-05/0316.html
http://archives.neohapsis.com/archives/bugtraq/2004-06/0002.html
http://archives.neohapsis.com/archives/bugtraq/2004-06/0020.html
http://archives.neohapsis.com/archives/bugtraq/2004-06/0190.html
http://secunia.com/advisories/11754 PatchVendor Advisory
http://web.archive.org/web/20040823075750/http://www.linksys.com/download/firmware.asp?fwid=201 Patch
http://www.nwfusion.com/news/2004/0607confuse.html
http://www.osvdb.org/6577
http://www.securityfocus.com/archive/1/365175
http://www.securityfocus.com/archive/1/365227/30/0/threaded
http://www.securityfocus.com/bid/10441 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/16274

Track CVE-2004-2606 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-1247Linksys wrt54g permissions and access controls vulnerabilityThe web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers…EPSS 5.2%10.0CVE-2008-1268Linksys wrt54g improper authentication vulnerabilityThe FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to estab…EPSS 2.5%7.8CVE-2008-1265Linksys wrt54g improper input validation vulnerabilityThe Linksys WRT54G router allows remote attackers to cause a denial of service (device restart) via a long username and password to the FTP interface.EPSS 1.6%7.5CVE-2011-4499Cisco linksys wrt54g router firmware vulnerabilityThe UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware b…EPSS 1.3%7.5CVE-2008-1264Linksys wrt54g improper authentication vulnerabilityThe Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a fil…EPSS 3.1%7.5CVE-2006-2559Linksys wrt54g vulnerabilityLinksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP reque…EPSS 1.7%7.5CVE-2005-2799Linksys WRT54G apply.cgi buffer overflow allows remote code executionA buffer overflow exists in apply.cgi on the Linksys WRT54G router (versions 3.01.03, 3.03.6, and possibly others before 4.20.7). A long HTTP POST re…EPSS 71%analysed7.5CVE-2005-2914Linksys wrt54g vulnerabilityezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authenticat…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2004-2606), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.