Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-4502


The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.


Published

2011-11-22T11:55:05.043

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System edimax br-6104k_router_firmware 3.21 Yes
Hardware edimax br-6104k - Yes
Operating System canyon-tech cn-wf512_router_firmware 1.83 Yes
Operating System canyon-tech cn-wf514_router_firmware 2.08 Yes
Hardware canyon-tech cn-wf512 - Yes
Hardware canyon-tech cn-wf514 - Yes
Operating System edimax 6114wg_router_firmware 1.83 Yes
Operating System edimax 6114wg_router_firmware 2.08 Yes
Hardware edimax 6114wg - Yes
Operating System sitecom wl-153_router_firmware 1.31 Yes
Operating System sitecom wl-153_router_firmware 1.34 Yes
Hardware sitecom wl-153 - Yes
Operating System sweex lb000021_router_firmware 3.15 Yes
Hardware sweex lb000021 - Yes

References