Remote Linksys 0-Day Root Exploit Uncovered
Orome1 writes "DefenseCode researchers have uncovered a remote root access vulnerability in the default installation of Linksys routers. They contacted Cisco and shared a detailed vulnerability description along with the PoC exploit for the vulnerability. Cisco claimed that the vulnerability was already fixed in the latest firmware release, which turned out to be incorrect. The latest Linksys firmware (4.30.14) and all previous versions are still vulnerable."
It is really odd. WRT54GL is target to people who will flash it with custom firmwares. Why would use one of those with stock firmware? If you are not going to hack it, just buy another model (better and/or cheaper).
Anyone running stock on a WRT54GL deserves to be hacked.
morcego