PT-2011-4965 · Sweex+3 · Sweex Lb000021+5
Daniel Garcia
·
Published
2011-11-22
·
Updated
2013-01-24
·
CVE-2011-4501
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Edimax BR-6104K versions prior to 3.25
Edimax 6114Wg version not specified
Canyon-Tech CN-WF512 version 1.83
Canyon-Tech CN-WF514 version 2.08
Sitecom WL-153 versions prior to 1.39
Sweex LB000021 version 3.15
Description
The issue allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
Recommendations
For Edimax BR-6104K, update to firmware version 3.25 or later.
For Edimax 6114Wg, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Canyon-Tech CN-WF512, consider disabling the UPnP functionality until a patch is available.
For Canyon-Tech CN-WF514, consider disabling the UPnP functionality until a patch is available.
For Sitecom WL-153, update to firmware version 1.39 or later.
For Sweex LB000021, consider disabling the UPnP functionality until a patch is available.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Canyon-Tech Cn-Wf512
Canyon-Tech Cn-Wf514
Edimax 6114Wg
Edimax Br-6104K
Sitecom Wl-153
Sweex Lb000021