PT-2006-3507 · Edimax · Edimax Br-6104K

Published

2006-05-24

·

Updated

2024-02-14

·

CVE-2006-2561

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Edimax BR-6104K router (affected versions not specified)
Description The issue allows remote attackers to bypass access restrictions and conduct unauthorized operations. This is achieved via a UPnP request with a modified InternalClient parameter, possibly within NewInternalClient, which is not validated. An example of exploitation is using the AddPortMapping function to forward arbitrary traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2006-2561

Affected Products

Edimax Br-6104K