« Back to list

CVE-2006-4523

Status: ModifiedMedium (5)—💥 Exploit

The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequence in a GET request.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2006-4523",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-09-01T23:04:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/21583",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1489",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mexhackteam.org/prethoonker/DoS_ADV_2Wire.txt",
      "tags": [
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443906/100/100/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19634",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28578",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/2246",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/21583",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/1489",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mexhackteam.org/prethoonker/DoS_ADV_2Wire.txt",
      "tags": [
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443906/100/100/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19634",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28578",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/2246",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequence in a GET request."
    },
    {
      "lang": "es",
      "value": "La interfaz de administración basada en web en los modems y routers de la serie HomePortal y OfficePortal de 2Wire, Inc. permite a atacantes remotos provocar una denegación de servicio (caída) mediante una secuencia CRLF en una petición GET."
    }
  ],
  "lastModified": "2026-06-16T22:29:16.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB6F6F3D-8169-4D9C-B8F9-C138CD6F9641"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:100s:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BF922E0-B557-4DF8-8FAF-46D8D47933E6"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:100w:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "179376AD-7DF3-4741-8644-C2B0B4AD7601"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:1000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0F85FA3-744D-4197-AB65-75E0E25B5435"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:1000s:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38D13D75-7211-48C9-9EFB-4094812CC299"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:1000sw:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04C28D41-480D-484C-91A8-59CBF20FA960"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:1000w:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "958F3933-5DD6-45EB-BFC9-AC2DB09E3ECC"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:homeportal:1500w:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7EE4B91-334E-4122-9158-0041A6F1E7DB"
            },
            {
              "criteria": "cpe:2.3:a:2wire_inc:officeportal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D456BF0C-B2F6-471D-9698-698167319400"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}