← Back to CVE List
Vulnerability Intelligence Report

CVE-2011-4501

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:4.45%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
edimax br-6104k_router_firmware 3.21
edimax br-6104k all
canyon-tech cn-wf512_router_firmware 1.83
canyon-tech cn-wf514_router_firmware 2.08
canyon-tech cn-wf512 all
canyon-tech cn-wf514 all
edimax 6114wg_router_firmware 1.83, 2.08
edimax 6114wg all
sitecom wl-153_router_firmware 1.31, 1.34
sitecom wl-153 all
sweex lb000021_router_firmware 3.15
sweex lb000021 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.445%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2011-11-22T00:00:00
Published2011-11-22T11:00:00
Last Updated2024-09-17T01:26:26

LINK COPIED TO CLIPBOARD