The 2008 Pwnie Nominee For Most Over-Hyped Bug

BT Home Hub authentication bypass (CVE-2008-5383 and CVE-2008-5384)

Adrian ‘pagvac’ Pastor

GNUCITIZEN and pagvac initiated a media blitz over this vulnerability which allows a malicious web page to use a CSRF attack to bypass authentication and modify the settings on the most popular home DSL router in the UK. This could allow a remote site to disable your firewall, modify your DNS server settings, or enable remote administration of your router. The bug was real, but it was accompanied by such a massive media campaign that it surely deserves a nomination.

(CVE-2008-5383 and CVE-2008-5384)