Small Net Builder
The embedded HTTP admin server in many Linksys routers has two key security vulnerabilities. One allows local (and Remote, i.e. WAN, if the 'Remote Admin' feature is enabled) users to gain control of the router by using any a file with a .xml extension. The other vulnerability is related to buffer overflows.
See this page from CoreLabs for a detailed report, list of affected products, and actions to take.
Source: Small Net Builder
http://www.smallnetbuilder.com/FAQ-33-Linksys+Wire











