CVE-2011-4504 Information

Description

The UPnP IGD implementation in the Pseudo ICS UPnP software on the ZyXEL P-330W allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface related to an \external forwarding\ vulnerability.

Reference

http://www.kb.cert.org/vuls/id/357851 http://www.upnp-hacks.org/suspect.html

Share on: