CVE-2006-2560: High severity Sitecom WL-153 router firmware vulnerability
Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2560?
CVE-2006-2560 is considered to have a medium severity due to its potential for unauthorized access and operations on the affected router.
How do I fix CVE-2006-2560?
To fix CVE-2006-2560, upgrade the Sitecom WL-153 router firmware to version 1.38 or later.
What type of attack does CVE-2006-2560 enable?
CVE-2006-2560 enables attackers to bypass access restrictions and forward arbitrary traffic using modified UPnP requests.
Which devices are affected by CVE-2006-2560?
CVE-2006-2560 affects Sitecom WL-153 routers running firmware versions up to 1.34 and specifically version 1.31.
Is CVE-2006-2560 related to UPnP vulnerabilities?
Yes, CVE-2006-2560 is a vulnerability stemming from improper validation of UPnP requests in the Sitecom WL-153 router.