CVE-2011-4501
CVE-2011-4501 is a critical vulnerability affecting the UPnP IGD implementation in various routers from Edimax, Canyon-Tech, Sitecom, and Sweex. It allows remote, unauthenticated attackers to establish arbitrary port mappings by sending a crafted SOAP request to the WAN interface. This vulnerability carries a CVSS score of 10.0, indicating a severe risk with complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, suggesting awareness among security researchers.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.21CPE matchmatch criteria | cpe:2.3:o:edimax:br-6104k_router_firmware:3.21:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:edimax:br-6104k:-:*:*:*:*:*:*:* | ||
1.83CPE matchmatch criteria | cpe:2.3:o:canyon-tech:cn-wf512_router_firmware:1.83:*:*:*:*:*:*:* | ||
2.08CPE matchmatch criteria | cpe:2.3:o:canyon-tech:cn-wf514_router_firmware:2.08:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:canyon-tech:cn-wf512:-:*:*:*:*:*:*:* |
CVSS Data
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploit Intelligence
Social Chatter
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation
Remediation records are not available for this CVE.