Linksys WRT54 Access Point apply.cgi Buffer Overflow
cve CVE-2005-2799 2 sources, 4 claims · Watch
Metasploit exploit modules writes:
This module exploits a stack buffer overflow in apply.cgi on the Linksys WRT54G and WRT54GS routers. According to iDefense who discovered this vulnerability, all WRT54G versions prior to 4.20.7 and all WRT54GS version prior to 1.05.2 may be affected. the claim
This module exploits a stack buffer overflow in apply.cgi on the Linksys WRT54G and WRT54GS routers. According to iDefense who discovered this vulnerability, all WRT54G versions prior to 4.20.7 and all WRT54GS version prior to 1.05.2 may be affected. the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | Metasploitreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2005-2799;OSVDB-19389",
"date_added": "2010-09-24",
"date_published": "2010-09-24",
"date_updated": "2011-03-06",
"description": "Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
"file": "exploits/hardware/remote/16854.rb",
"id": "16854",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — |
| Author author | Raphael Rigoreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Raphael Rigo",
"codes": "CVE-2005-2799;OSVDB-19389",
"date_added": "2005-09-12",
"date_published": "2005-09-13",
"date_updated": "",
"description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
"file": "exploits/cgi/remote/10028.rb",
"id": "10028",
"platform": "cgi",
"port": "80",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — | |
| Platform platform not compared | Exploit-DB | cgireceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Raphael Rigo",
"codes": "CVE-2005-2799;OSVDB-19389",
"date_added": "2005-09-12",
"date_published": "2005-09-13",
"date_updated": "",
"description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
"file": "exploits/cgi/remote/10028.rb",
"id": "10028",
"platform": "cgi",
"port": "80",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — |
| Platform platform not compared | hardwarereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2005-2799;OSVDB-19389",
"date_added": "2010-09-24",
"date_published": "2010-09-24",
"date_updated": "2011-03-06",
"description": "Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
"file": "exploits/hardware/remote/16854.rb",
"id": "16854",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — | |
| Platform platform not compared | Metasploit exploit modules | Linuxreceipt
What the source handed over{
"aliases": [],
"arch": "mipsle",
"author": [
"Raphael Rigo <devel-metasploit@syscall.eu>",
"Julien Tinnes <julien@cr0.org>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": false,
"default_credential": false,
"description": "This module exploits a stack buffer overflow in apply.cgi on the Linksys WRT54G and WRT54GS routers.\n According to iDefense who discovered this vulnerability, all WRT54G versions prior to\n 4.20.7 and all WRT54GS version prior to 1.05.2 may be affected.",
"disclosure_date": "2005-09-13",
"fullname": "exploit/linux/http/linksys_apply_cgi",
"is_install_path": true,
"mod_time": "2025-06-23 12:43:46 +0000",
"name": "Linksys WRT54 Access Point apply.cgi Buffer Overflow",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/linux/http/linksys_apply_cgi.rb",
"platform": "Linux",
"post_auth": false,
"rank": 500,
"ref_name": "linux/http/linksys_apply_cgi",
"references": [
"CVE-2005-2799",
"OSVDB-19389",
"URL-http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=305"
],
"rport": 80,
"session_types": false,
"targets": [
"Generic",
"Version 1.42.2",
"Version 2.02.6beta1",
"Version 2.02.7_ETSI",
"Version 3.03.6",
"Version 4.00.7",
"Version 4.20.06"
],
"type": "exploit"
} | — |
| Platform platform not compared | Linux,Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd, mipsle",
"author": [
"Michael Messner <devnull@s3cur1ty.de>",
"juan vazquez <juan.vazquez@metasploit.com>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": false,
"default_credential": false,
"description": "Some Linksys Routers are vulnerable to an authenticated OS command injection in\n the Web Interface. Default credentials are admin/admin or admin/password. Since it\n is a blind os command injection vulnerability, there is no output for the executed\n command when using the cmd generic payload. A ping command against a controlled\n system could be used for testing purposes. The user must be prudent when using this\n module since it modifies the router configuration while exploitation, even when it\n tries to restore previous values.",
"disclosure_date": "2013-01-18",
"fullname": "exploit/linux/http/linksys_wrt54gl_apply_exec",
"is_install_path": true,
"mod_time": "2026-04-02 17:30:43 +0000",
"name": "Linksys WRT54GL apply.cgi Command Execution",
"needs_cleanup": true,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/linux/http/linksys_wrt54gl_apply_exec.rb",
"platform": "Linux,Unix",
"post_auth": true,
"rank": 0,
"ref_name": "linux/http/linksys_wrt54gl_apply_exec",
"references": [
"CVE-2005-2799",
"OSVDB-89912",
"BID-57459",
"EDB-24202",
"URL-http://www.s3cur1ty.de/m1adv2013-001"
],
"rport": 80,
"session_types": false,
"targets": [
"CMD",
"Linux mipsel Payload"
],
"type": "exploit"
} | — | |
| Rank rank | Metasploit exploit modules | 0 Manual. Not automated; the operator configures it. receipt
What the source handed over{
"aliases": [],
"arch": "cmd, mipsle",
"author": [
"Michael Messner <devnull@s3cur1ty.de>",
"juan vazquez <juan.vazquez@metasploit.com>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": false,
"default_credential": false,
"description": "Some Linksys Routers are vulnerable to an authenticated OS command injection in\n the Web Interface. Default credentials are admin/admin or admin/password. Since it\n is a blind os command injection vulnerability, there is no output for the executed\n command when using the cmd generic payload. A ping command against a controlled\n system could be used for testing purposes. The user must be prudent when using this\n module since it modifies the router configuration while exploitation, even when it\n tries to restore previous values.",
"disclosure_date": "2013-01-18",
"fullname": "exploit/linux/http/linksys_wrt54gl_apply_exec",
"is_install_path": true,
"mod_time": "2026-04-02 17:30:43 +0000",
"name": "Linksys WRT54GL apply.cgi Command Execution",
"needs_cleanup": true,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/linux/http/linksys_wrt54gl_apply_exec.rb",
"platform": "Linux,Unix",
"post_auth": true,
"rank": 0,
"ref_name": "linux/http/linksys_wrt54gl_apply_exec",
"references": [
"CVE-2005-2799",
"OSVDB-89912",
"BID-57459",
"EDB-24202",
"URL-http://www.s3cur1ty.de/m1adv2013-001"
],
"rport": 80,
"session_types": false,
"targets": [
"CMD",
"Linux mipsel Payload"
],
"type": "exploit"
} | — |
| Rank rank | 500 Great. Detects the target automatically, or uses an application-specific return address. receipt
What the source handed over{
"aliases": [],
"arch": "mipsle",
"author": [
"Raphael Rigo <devel-metasploit@syscall.eu>",
"Julien Tinnes <julien@cr0.org>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": false,
"default_credential": false,
"description": "This module exploits a stack buffer overflow in apply.cgi on the Linksys WRT54G and WRT54GS routers.\n According to iDefense who discovered this vulnerability, all WRT54G versions prior to\n 4.20.7 and all WRT54GS version prior to 1.05.2 may be affected.",
"disclosure_date": "2005-09-13",
"fullname": "exploit/linux/http/linksys_apply_cgi",
"is_install_path": true,
"mod_time": "2025-06-23 12:43:46 +0000",
"name": "Linksys WRT54 Access Point apply.cgi Buffer Overflow",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/linux/http/linksys_apply_cgi.rb",
"platform": "Linux",
"post_auth": false,
"rank": 500,
"ref_name": "linux/http/linksys_apply_cgi",
"references": [
"CVE-2005-2799",
"OSVDB-19389",
"URL-http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=305"
],
"rport": 80,
"session_types": false,
"targets": [
"Generic",
"Version 1.42.2",
"Version 2.02.6beta1",
"Version 2.02.7_ETSI",
"Version 3.03.6",
"Version 4.00.7",
"Version 4.20.06"
],
"type": "exploit"
} | — | |
| Type type | Exploit-DB | remotereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Raphael Rigo",
"codes": "CVE-2005-2799;OSVDB-19389",
"date_added": "2005-09-12",
"date_published": "2005-09-13",
"date_updated": "",
"description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
"file": "exploits/cgi/remote/10028.rb",
"id": "10028",
"platform": "cgi",
"port": "80",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — |
| Verified verified | Exploit-DB | truereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Raphael Rigo",
"codes": "CVE-2005-2799;OSVDB-19389",
"date_added": "2005-09-12",
"date_published": "2005-09-13",
"date_updated": "",
"description": "Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit)",
"file": "exploits/cgi/remote/10028.rb",
"id": "10028",
"platform": "cgi",
"port": "80",
"screenshot_url": "",
"source_url": "",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — |
exploit
| Linksys WRT54 Access Point apply.cgi Buffer Overflow zetlyn/cve-metasploit · 2005-09-13 | platform Linux rank 500 | source |
| Linksys WRT54GL apply.cgi Command Execution zetlyn/cve-metasploit · 2013-01-18 | platform Linux,Unix rank 0 | source |
| Linksys WRT54G < 4.20.7 / WRT54GS < 1.05.2 - 'apply.cgi' Remote Buffer Overflow (Metasploit) zetlyn/cve-exploitdb · 2005-09-13 | author Raphael Rigo platform cgi type remote verified true | source |
| Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit) zetlyn/cve-exploitdb · 2010-09-24 | author Metasploit platform hardware type remote verified true | source |