« Volver al listado

CVE-2011-4502

Estado: ModificadaAlta (10)—

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (12)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4502",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-11-22T11:55:05.043",
  "references": [
    {
      "url": "http://www.kb.cert.org/vuls/id/357851",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.upnp-hacks.org/devices.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.upnp-hacks.org/suspect.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/357851",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.upnp-hacks.org/devices.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.upnp-hacks.org/suspect.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters."
    },
    {
      "lang": "es",
      "value": "La implementación de UPnP IGD en Edimax EdiLinux en el Edimax BR-6104K con firmware anterior a v3.25 Edimax 6114Wg, Canyon-Tech CN-WF512 con firmware anterior a v1.83, Canyon-Tech CN-WF514 con firmware anterior a v2.08, Sitecom WL-153 con firmware anterior a v1.39, y Sweex LB000021 con firmware anterior a v3.15, permite a atacantes remotos ejecutar comandos de su elección a través de metacaracteres shell."
    }
  ],
  "lastModified": "2026-06-16T23:34:56.933",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:edimax:br-6104k_router_firmware:3.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D45ACA8-D8A4-4354-8B7D-ADE3330C9BEC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:edimax:br-6104k:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "160DBE73-D5FA-4A1B-809B-A923E8F39A64"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canyon-tech:cn-wf512_router_firmware:1.83:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EF3228F-22AC-4C90-998F-CA234E04C93E"
            },
            {
              "criteria": "cpe:2.3:o:canyon-tech:cn-wf514_router_firmware:2.08:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6EB70515-F398-492F-8F99-6572EF3A41AA"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:canyon-tech:cn-wf512:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85C0B475-BCF0-4370-AB61-CB30567B1394"
            },
            {
              "criteria": "cpe:2.3:h:canyon-tech:cn-wf514:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9833088-083B-44BE-82B4-EA41E1902255"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:edimax:6114wg_router_firmware:1.83:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6C80B5C-7882-4780-A4B5-5D00BD779EC0"
            },
            {
              "criteria": "cpe:2.3:o:edimax:6114wg_router_firmware:2.08:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72E44F32-FFCA-4FE0-B6B6-B21FE1D9690A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:edimax:6114wg:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "028C6A7D-22A5-47B8-BE81-75AE2A94EBF2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sitecom:wl-153_router_firmware:1.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDD603E5-B223-4ABC-A3B8-E1925699701B"
            },
            {
              "criteria": "cpe:2.3:o:sitecom:wl-153_router_firmware:1.34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5132DF5B-C8BE-4B63-9C23-771014E91091"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sitecom:wl-153:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBED964D-46D2-4359-91A9-E2A2D4D719A3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sweex:lb000021_router_firmware:3.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BE22FB4-E8B4-4DF5-AE4C-CEDE18FAE681"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sweex:lb000021:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E0E3D83-38D0-42A8-90AC-C0CAF453ED53"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}