CVE-2011-4500
The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- cisco/linksys wrt54gx router firmware · linksys/wrt54gx
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/357851US Government Resource
- http://www.upnp-hacks.org/devices.html
- http://www.kb.cert.org/vuls/id/357851US Government Resource
- http://www.upnp-hacks.org/devices.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.