First published: Tue Nov 22 2011(Updated: )
The UPnP IGD implementation on SpeedTouch 5x6 devices with firmware before 6.2.29 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alcatel Speedtouch 5x6 Router Firmware | <=6.2 | |
Alcatel Speedtouch 5x6 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4505 has a medium severity rating due to its potential to allow unauthorized port mapping.
To fix CVE-2011-4505, upgrade the SpeedTouch 5x6 router firmware to version 6.2.29 or later.
CVE-2011-4505 specifically affects SpeedTouch 5x6 devices with firmware versions prior to 6.2.29.
Yes, CVE-2011-4505 can be exploited remotely by sending crafted SOAP requests to the WAN interface.
The primary risk of CVE-2011-4505 is that it allows attackers to create arbitrary port mappings, potentially leading to unauthorized access.