CVE-2011-4503 describes a vulnerability in the UPnP IGD implementation of Broadcom Linux on the Sitecom WL-111 router, allowing remote attackers to establish arbitrary port mappings. This is due to an "external forwarding" flaw, enabling attackers to send a UPnP AddPortMapping action via a SOAP request to the WAN interface. With a CVSS score of 7.5, this vulnerability is considered high severity, as it can lead to partial confidentiality, integrity, and availability impacts without requiring authentication or complex attack vectors. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the CVE has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:broadcom:broadcom_linux:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:sitecom:wl-111:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.