lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <201608142140.u7ELeitO002027@sf01web3.securityfocus.com> Date: Sun, 14 Aug 2016 21:40:44 GMT From: samhuntley84@...il.com To: bugtraq@...urityfocus.com Subject: Linksys E1200 and E2500 (Missing authorization on parental control) Linksys E1200 hardware version 2.2 and firmware version 2.0.07 (build 2) suffer from missing authorization control on parental control page. This allows an attacker to change the parental controls set up by parents to keep kids safe from visiting adult sites and probably compromise a kid’s device. Info at http://www.samuelhuntley.com/?p=132 http://www.samuelhuntley.com/?p=143 Initial disclosure date: 04/12/16 Fixed date as per Linksys contact: 7/4/16 Linksys contact: Benjamin Samuels, Calvin Clark (security@...ksys.com)
Powered by blists - more mailing lists