Help my Linksys WRT54G router was broken into using the "curl" command

It's way too easy to break into the Linksys WRT54G router!

Instantly bypassing the administrator password, my fifteen-year old neighbor broke into my Linksys WRT54G router (firmware revision v1.0.0.6) in ten seconds simply by sending this one "curl" command to it via the Internet from his home next door!

c:\> curl -d "SecurityMode=0&layout=en" http://192.168.0.1/Security.tri This kid was kind enough to knock on my door today to tell me to fix it.

I invited him in, and from inside my own house, he showed me the Linksys WRT54G command above which immediately disabled all my wireless security WITHOUT him having to enter any password!

He showed me how to disable remote administration but he said the vulnerability still exists until I get a new router. I can't believe everyone with a Linksys WRT54G router is throwing it in the garbage.

Where/how can I find a firmware update that protects me from this vulnerability?

read more and respond »

Posted 5 years ago by Debbie Hurley in Wireless Networking

Report misuse

Image for Help my Linksys WRT54G router was broken into using the "curl" command