PT-2011-4965 · Sweex+3 · Sweex Lb000021+5

Daniel Garcia

·

Published

2011-11-22

·

Updated

2013-01-24

·

CVE-2011-4501

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Edimax BR-6104K versions prior to 3.25 Edimax 6114Wg version not specified Canyon-Tech CN-WF512 version 1.83 Canyon-Tech CN-WF514 version 2.08 Sitecom WL-153 versions prior to 1.39 Sweex LB000021 version 3.15
Description The issue allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
Recommendations For Edimax BR-6104K, update to firmware version 3.25 or later. For Edimax 6114Wg, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Canyon-Tech CN-WF512, consider disabling the UPnP functionality until a patch is available. For Canyon-Tech CN-WF514, consider disabling the UPnP functionality until a patch is available. For Sitecom WL-153, update to firmware version 1.39 or later. For Sweex LB000021, consider disabling the UPnP functionality until a patch is available.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4501

Affected Products

Canyon-Tech Cn-Wf512
Canyon-Tech Cn-Wf514
Edimax 6114Wg
Edimax Br-6104K
Sitecom Wl-153
Sweex Lb000021