Vulnerability Intelligence Report
CVE-2011-4502
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:5.80%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| edimax | br-6104k_router_firmware | 3.21 |
| edimax | br-6104k | all |
| canyon-tech | cn-wf512_router_firmware | 1.83 |
| canyon-tech | cn-wf514_router_firmware | 2.08 |
| canyon-tech | cn-wf512 | all |
| canyon-tech | cn-wf514 | all |
| edimax | 6114wg_router_firmware | 1.83, 2.08 |
| edimax | 6114wg | all |
| sitecom | wl-153_router_firmware | 1.31, 1.34 |
| sitecom | wl-153 | all |
| sweex | lb000021_router_firmware | 3.15 |
| sweex | lb000021 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
5.801%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2011-11-22T00:00:00 |
| Published | 2011-11-22T11:00:00 |
| Last Updated | 2024-09-17T00:25:31 |
Community Chatter & Buzz