« Volver al listado

CVE-2006-2559

Estado: ModificadaAlta (7.5)—

Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-2559",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-05-24T01:02:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/20161",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1016134",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityview.org/dutch-student-finds-a-bug-in-upnp.html",
      "tags": [
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityview.org/how-does-the-upnp-flaw-works.html",
      "tags": [
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1909",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26707",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20161",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1016134",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityview.org/dutch-student-finds-a-bug-in-upnp.html",
      "tags": [
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityview.org/how-does-the-upnp-flaw-works.html",
      "tags": [
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1909",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26707",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic."
    }
  ],
  "lastModified": "2026-06-16T22:25:19.557",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:1.42.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51DC73D9-CBB8-4683-BB21-3AA0F9468F18"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:2.00.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AF3AB9D-CE52-42CF-9FD7-ECB83495C3AE"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:2.02.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BD5B2C5-E393-45E4-B847-4CFF7DA972B2"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:2.04.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E807422-77F7-4B91-9397-D974F339801C"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:2.04.4_non_default:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6EF028B3-314E-4F04-8CBB-87314907AB1E"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:3.01.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2930D914-EBA6-48D7-8D61-A7B0C3A140BB"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:3.03.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A9F2EDC-30F5-480E-8E6E-4D0C553AE281"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g:4.00.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95D095E4-B0FC-4BFF-9E72-DFDE308A9062"
            },
            {
              "criteria": "cpe:2.3:h:linksys:wrt54g_v5:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E98A579C-A78D-44B3-B12B-8EF75A2A5CFB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}