CVE-2010-1573 is a critical vulnerability affecting Linksys WAP54Gv3 firmware versions 3.04.03 and earlier. It stems from the use of a hard-coded debug interface accessible via specific web pages, utilizing a default username "Gemtek" and password "gemtekswd." This flaw allows unauthenticated remote attackers to execute arbitrary commands by manipulating data parameters within Debug_command_page.asp and debug.cgi. With a CVSS score of 9.8, this vulnerability presents a critical risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Despite its high severity and EPSS score, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.04.03CPE matchmatch criteria | cpe:2.3:o:linksys:wap54g_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.