CVE-2011-4499 (CNNVD-201111-361)
中文标题:
Cisco Linksys WRT54G ‘Broadcom UPnP’配置错误漏洞
英文标题:
The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware bef...
漏洞描述
中文描述:
Cisco Linksys WRT54G多个版本的Broadcom UPnP栈的UPnP IGD安装启用中存在漏洞。远程攻击者可通过发送SOAP请求的UPnP AddPortMapping操作到WAN接口建立任意端口映射,该漏洞与 "external forwarding" 漏洞有关。 这些版本包括:Cisco Linksys WRT54G with firmware 4.30.5之前版本, WRT54GS v1至v3 with firmware 4.71.1之前版本以及WRT54GS v4 with firmware 1.06.1之前版本。
英文描述:
The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | linksys_wrt54g_router_firmware | * | - | - |
cpe:2.3:a:cisco:linksys_wrt54g_router_firmware:*:*:*:*:*:*:*:*
|
| cisco | linksys_wrt54g_router_firmware | 3.03.9 | - | - |
cpe:2.3:a:cisco:linksys_wrt54g_router_firmware:3.03.9:*:*:*:*:*:*:*
|
| cisco | linksys_wrt54g_router_firmware | 4.20.7 | - | - |
cpe:2.3:a:cisco:linksys_wrt54g_router_firmware:4.20.7:*:*:*:*:*:*:*
|
| linksys | wrt54g | * | - | - |
cpe:2.3:h:linksys:wrt54g:*:*:*:*:*:*:*:*
|
| linksys | wrt54g | 2.2 | - | - |
cpe:2.3:h:linksys:wrt54g:2.2:*:*:*:*:*:*:*
|
| cisco | linksys_wrt54gs_router_firmware | * | - | - |
cpe:2.3:a:cisco:linksys_wrt54gs_router_firmware:*:*:*:*:*:*:*:*
|
| cisco | linksys_wrt54gs_router_firmware | 2.09.1 | - | - |
cpe:2.3:a:cisco:linksys_wrt54gs_router_firmware:2.09.1:*:*:*:*:*:*:*
|
| linksys | wrt54gs | 1.0 | - | - |
cpe:2.3:h:linksys:wrt54gs:1.0:*:*:*:*:*:*:*
|
| linksys | wrt54gs | 2.0 | - | - |
cpe:2.3:h:linksys:wrt54gs:2.0:*:*:*:*:*:*:*
|
| linksys | wrt54gs | 3.0 | - | - |
cpe:2.3:h:linksys:wrt54gs:3.0:*:*:*:*:*:*:*
|
| linksys | wrt54gs | 4.0 | - | - |
cpe:2.3:h:linksys:wrt54gs:4.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:L/Au:N/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2011-4499 |
2025-11-11 15:18:25 | 2025-11-11 07:33:18 |
| NVD | nvd_CVE-2011-4499 |
2025-11-11 14:53:44 | 2025-11-11 07:42:08 |
| CNNVD | cnnvd_CNNVD-201111-361 |
2025-11-11 15:09:14 | 2025-11-11 07:49:58 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 配置错误
- cnnvd_id: 未提取 -> CNNVD-201111-361
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 11
- data_sources: ['cve'] -> ['cve', 'nvd']