Vulnerability record · CVE-2005-2799 · published 15 September 2005
CVE-2005-2799: Linksys WRT54G apply.cgi buffer overflow allows remote code execution
Linksys · Wrt54g
A buffer overflow exists in apply.cgi on the Linksys WRT54G router (versions 3.01.03, 3.03.6, and possibly others before 4.20.7). A long HTTP POST request can overflow the buffer, allowing remote attackers to execute arbitrary code on the device. The flaw is remotely reachable and requires no authentication, making it a serious risk for exposed routers.
Description
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and has a high EPSS score, though it is not listed in KEV and affects older firmware.
What it is
A buffer overflow exists in apply.cgi on the Linksys WRT54G router (versions 3.01.03, 3.03.6, and possibly others before 4.20.7). A long HTTP POST request can overflow the buffer, allowing remote attackers to execute arbitrary code on the device. The flaw is remotely reachable and requires no authentication, making it a serious risk for exposed routers.
Impact
An unauthenticated remote attacker can execute arbitrary code on the router, potentially taking full control of the device and its network traffic. This could lead to persistent compromise, traffic interception, or use of the router as a pivot point.
Attack surface
The vulnerability is reached over the network via HTTP POST requests to apply.cgi on the router's web interface. No authentication or user interaction is required according to the CVSS vector (AV:N/AC:L/Au:N).
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit references beyond vendor advisory and patch tags. EPSS indicates a high probability of exploitation activity (0.70753, 99.366th percentile), but no public exploit details are included in the supplied data.
What to do
- Upgrade the WRT54G firmware to version 4.20.7 or later as indicated by the vendor advisory.
- If patching is not possible, disable remote administration and restrict access to the router's web interface to trusted internal networks only.
- Place the router behind a firewall that blocks inbound HTTP access to its management interface from untrusted networks.
- Monitor vendor advisories for updated firmware and apply promptly; replace end-of-life devices that no longer receive fixes.
Detection
- Inspect HTTP POST requests to apply.cgi for unusually long payloads or malformed parameters that could indicate overflow attempts.
- Monitor router logs and network traffic for unexpected outbound connections or process behavior following HTTP POST requests to the management interface.
- Use network intrusion detection signatures for buffer overflow attempts against embedded web servers if available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.idefense.com/application/poi/display?id=305&type=vulnerabilities | PatchVendor Advisory |
| http://www.idefense.com/application/poi/display?id=305&type=vulnerabilities | PatchVendor Advisory |
Track CVE-2005-2799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.