CVE-2011-4502

EUVD-2011-4428
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
edimaxbr-6104k_router_firmware
3.21
edimaxbr-6104k
-
canyon-techcn-wf512_router_firmware
1.83
canyon-techcn-wf514_router_firmware
2.08
canyon-techcn-wf512
-
canyon-techcn-wf514
-
edimax6114wg_router_firmware
1.83
edimax6114wg_router_firmware
2.08
edimax6114wg
-
sitecomwl-153_router_firmware
1.31
sitecomwl-153_router_firmware
1.34
sitecomwl-153
-
sweexlb000021_router_firmware
3.15
sweexlb000021
-
𝑥
= Vulnerable software versions