Linksys WRT54 Access Point apply.cgi Buffer Overflow

cve CVE-2005-2799 2 sources, 4 claims · Watch

Metasploit exploit modules writes:
This module exploits a stack buffer overflow in apply.cgi on the Linksys WRT54G and WRT54GS routers. According to iDefense who discovered this vulnerability, all WRT54G versions prior to 4.20.7 and all WRT54GS version prior to 1.05.2 may be affected. the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBMetasploit
receipt
Source
Exploit-DB
Its words
Metasploit
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2005-2799;OSVDB-19389",
  "date_added": "2010-09-24",
  "date_published": "2010-09-24",
  "date_updated": "2011-03-06",
  "description": "Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
  "file": "exploits/hardware/remote/16854.rb",
  "id": "16854",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Author
author
Raphael Rigo
receipt
Source
Exploit-DB
Its words
Raphael Rigo
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Raphael Rigo",
  "codes": "CVE-2005-2799;OSVDB-19389",
  "date_added": "2005-09-12",
  "date_published": "2005-09-13",
  "date_updated": "",
  "description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
  "file": "exploits/cgi/remote/10028.rb",
  "id": "10028",
  "platform": "cgi",
  "port": "80",
  "screenshot_url": "",
  "source_url": "",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Platform
platform
not compared
Exploit-DBcgi
receipt
Source
Exploit-DB
Its words
cgi
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Raphael Rigo",
  "codes": "CVE-2005-2799;OSVDB-19389",
  "date_added": "2005-09-12",
  "date_published": "2005-09-13",
  "date_updated": "",
  "description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
  "file": "exploits/cgi/remote/10028.rb",
  "id": "10028",
  "platform": "cgi",
  "port": "80",
  "screenshot_url": "",
  "source_url": "",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Platform
platform
not compared
hardware
receipt
Source
Exploit-DB
Its words
hardware
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2005-2799;OSVDB-19389",
  "date_added": "2010-09-24",
  "date_published": "2010-09-24",
  "date_updated": "2011-03-06",
  "description": "Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
  "file": "exploits/hardware/remote/16854.rb",
  "id": "16854",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Platform
platform
not compared
Metasploit exploit modulesLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 21:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "mipsle",
  "author": [
    "Raphael Rigo <devel-metasploit@syscall.eu>",
    "Julien Tinnes <julien@cr0.org>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": false,
  "default_credential": false,
  "description": "This module exploits a stack buffer overflow in apply.cgi on the Linksys WRT54G and WRT54GS routers.\n          According to iDefense who discovered this vulnerability, all WRT54G versions prior to\n          4.20.7 and all WRT54GS version prior to 1.05.2 may be affected.",
  "disclosure_date": "2005-09-13",
  "fullname": "exploit/linux/http/linksys_apply_cgi",
  "is_install_path": true,
  "mod_time": "2025-06-23 12:43:46 +0000",
  "name": "Linksys WRT54 Access Point apply.cgi Buffer Overflow",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/linux/http/linksys_apply_cgi.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 500,
  "ref_name": "linux/http/linksys_apply_cgi",
  "references": [
    "CVE-2005-2799",
    "OSVDB-19389",
    "URL-http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=305"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Generic",
    "Version 1.42.2",
    "Version 2.02.6beta1",
    "Version 2.02.7_ETSI",
    "Version 3.03.6",
    "Version 4.00.7",
    "Version 4.20.06"
  ],
  "type": "exploit"
}
—
Platform
platform
not compared
Linux,Unix
receipt
Source
Metasploit exploit modules
Its words
Linux,Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 21:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd, mipsle",
  "author": [
    "Michael Messner <devnull@s3cur1ty.de>",
    "juan vazquez <juan.vazquez@metasploit.com>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": false,
  "default_credential": false,
  "description": "Some Linksys Routers are vulnerable to an authenticated OS command injection in\n          the Web Interface. Default credentials are admin/admin or admin/password. Since it\n          is a blind os command injection vulnerability, there is no output for the executed\n          command when using the cmd generic payload. A ping command against a controlled\n          system could be used for testing purposes. The user must be prudent when using this\n          module since it modifies the router configuration while exploitation, even when it\n          tries to restore previous values.",
  "disclosure_date": "2013-01-18",
  "fullname": "exploit/linux/http/linksys_wrt54gl_apply_exec",
  "is_install_path": true,
  "mod_time": "2026-04-02 17:30:43 +0000",
  "name": "Linksys WRT54GL apply.cgi Command Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/linux/http/linksys_wrt54gl_apply_exec.rb",
  "platform": "Linux,Unix",
  "post_auth": true,
  "rank": 0,
  "ref_name": "linux/http/linksys_wrt54gl_apply_exec",
  "references": [
    "CVE-2005-2799",
    "OSVDB-89912",
    "BID-57459",
    "EDB-24202",
    "URL-http://www.s3cur1ty.de/m1adv2013-001"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "CMD",
    "Linux mipsel Payload"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules0
Manual. Not automated; the operator configures it.
receipt
Source
Metasploit exploit modules
Its words
0
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 21:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd, mipsle",
  "author": [
    "Michael Messner <devnull@s3cur1ty.de>",
    "juan vazquez <juan.vazquez@metasploit.com>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": false,
  "default_credential": false,
  "description": "Some Linksys Routers are vulnerable to an authenticated OS command injection in\n          the Web Interface. Default credentials are admin/admin or admin/password. Since it\n          is a blind os command injection vulnerability, there is no output for the executed\n          command when using the cmd generic payload. A ping command against a controlled\n          system could be used for testing purposes. The user must be prudent when using this\n          module since it modifies the router configuration while exploitation, even when it\n          tries to restore previous values.",
  "disclosure_date": "2013-01-18",
  "fullname": "exploit/linux/http/linksys_wrt54gl_apply_exec",
  "is_install_path": true,
  "mod_time": "2026-04-02 17:30:43 +0000",
  "name": "Linksys WRT54GL apply.cgi Command Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/linux/http/linksys_wrt54gl_apply_exec.rb",
  "platform": "Linux,Unix",
  "post_auth": true,
  "rank": 0,
  "ref_name": "linux/http/linksys_wrt54gl_apply_exec",
  "references": [
    "CVE-2005-2799",
    "OSVDB-89912",
    "BID-57459",
    "EDB-24202",
    "URL-http://www.s3cur1ty.de/m1adv2013-001"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "CMD",
    "Linux mipsel Payload"
  ],
  "type": "exploit"
}
—
Rank
rank
500
Great. Detects the target automatically, or uses an application-specific return address.
receipt
Source
Metasploit exploit modules
Its words
500
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 21:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "mipsle",
  "author": [
    "Raphael Rigo <devel-metasploit@syscall.eu>",
    "Julien Tinnes <julien@cr0.org>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": false,
  "default_credential": false,
  "description": "This module exploits a stack buffer overflow in apply.cgi on the Linksys WRT54G and WRT54GS routers.\n          According to iDefense who discovered this vulnerability, all WRT54G versions prior to\n          4.20.7 and all WRT54GS version prior to 1.05.2 may be affected.",
  "disclosure_date": "2005-09-13",
  "fullname": "exploit/linux/http/linksys_apply_cgi",
  "is_install_path": true,
  "mod_time": "2025-06-23 12:43:46 +0000",
  "name": "Linksys WRT54 Access Point apply.cgi Buffer Overflow",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/linux/http/linksys_apply_cgi.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 500,
  "ref_name": "linux/http/linksys_apply_cgi",
  "references": [
    "CVE-2005-2799",
    "OSVDB-19389",
    "URL-http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=305"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Generic",
    "Version 1.42.2",
    "Version 2.02.6beta1",
    "Version 2.02.7_ETSI",
    "Version 3.03.6",
    "Version 4.00.7",
    "Version 4.20.06"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBremote
receipt
Source
Exploit-DB
Its words
remote
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Raphael Rigo",
  "codes": "CVE-2005-2799;OSVDB-19389",
  "date_added": "2005-09-12",
  "date_published": "2005-09-13",
  "date_updated": "",
  "description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
  "file": "exploits/cgi/remote/10028.rb",
  "id": "10028",
  "platform": "cgi",
  "port": "80",
  "screenshot_url": "",
  "source_url": "",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—
Verified
verified
Exploit-DBtrue
receipt
Source
Exploit-DB
Its words
1
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Raphael Rigo",
  "codes": "CVE-2005-2799;OSVDB-19389",
  "date_added": "2005-09-12",
  "date_published": "2005-09-13",
  "date_updated": "",
  "description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
  "file": "exploits/cgi/remote/10028.rb",
  "id": "10028",
  "platform": "cgi",
  "port": "80",
  "screenshot_url": "",
  "source_url": "",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "1"
}
—

exploit

Linksys WRT54 Access Point apply.cgi Buffer Overflow
zetlyn/cve-metasploit · 2005-09-13
platform Linux rank 500 source
Linksys WRT54GL apply.cgi Command Execution
zetlyn/cve-metasploit · 2013-01-18
platform Linux,Unix rank 0 source
Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)
zetlyn/cve-exploitdb · 2005-09-13
author Raphael Rigo platform cgi type remote verified true source
Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)
zetlyn/cve-exploitdb · 2010-09-24
author Metasploit platform hardware type remote verified true source