CVE-2004-2749 describes a directory traversal vulnerability in the wra/public/wralogin component of 2Wire Gateway products, including HomePortal, allowing remote attackers to read arbitrary files by manipulating the 'return' parameter. With a CVSS score of 4.3 (medium severity), this vulnerability has a network attack vector, medium access complexity, and results in partial confidentiality impact without affecting integrity or availability. While not listed in CISA's KEV catalog, an exploit is publicly available on ExploitDB (EDB-23562), and it has garnered significant community discussion with over 10 mentions, indicating awareness despite no known active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
100sCPE matchmatch criteria | cpe:2.3:a:2wire:homeportal:100s:*:*:*:*:*:*:* | ||
100wCPE matchmatch criteria | cpe:2.3:a:2wire:homeportal:100w:*:*:*:*:*:*:* | ||
1000CPE matchmatch criteria | cpe:2.3:a:2wire:homeportal:1000:*:*:*:*:*:*:* | ||
1000sCPE matchmatch criteria | cpe:2.3:a:2wire:homeportal:1000s:*:*:*:*:*:*:* | ||
1000swCPE matchmatch criteria | cpe:2.3:a:2wire:homeportal:1000sw:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.