Sitecom's vulnerability profile centers on a narrow range of consumer wireless routers and networking devices, with the recurrent exposure driven by web-interface and firmware-handling weaknesses characteristic of embedded device platforms. The durable signal across its product line reflects input-validation and authentication issues including cross-site scripting, cross-site request forgery, OS command injection, hard-coded credentials, and remote file inclusion that are endemic to legacy router firmware design. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sitecom over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4501HIGH The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with f | Nov 22, 2011 | 10.0 | 32 | NO | NO |
CVE-2011-4502HIGH The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with f | Nov 22, 2011 | 10.0 | 31 | NO | NO |
CVE-2012-1921MEDIUM Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attackers to hijack the authentication of administrators for request | Aug 26, 2012 | 6.8 | 30 | NO | YES |
CVE-2012-1922MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators for requests that modify settin | Jan 24, 2013 | 6.8 | 28 | NO | YES |
CVE-2011-4503HIGH The UPnP IGD implementation in Broadcom Linux on the Sitecom WL-111 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP r | Nov 22, 2011 | 7.5 | 25 | NO | NO |
CVE-2006-2560HIGH Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClie | May 24, 2006 | 7.5 | 19 | NO | NO |
CVE-2024-40114MEDIUM A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicio | Jun 2, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-40113MEDIUM Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials. | Jun 2, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-40112MEDIUM A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the "language" cookie t | Jun 2, 2025 | 5.9 | 18 | NO | NO |
CVE-2013-6786MEDIUM Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DS | Jan 16, 2014 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sitecom.
Media articles that mention a CVE ID that affects a product developed by Sitecom — matched by CVE ID, not by vendor name.