The UPnP IGD implementation in Broadcom Linux on the Sitecom WL-111 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PBroadcom Linux
OSBroadcomwszystkie wersjeSitecom Wl 111
HWSitecomwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓ten sam vendor
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2018-1273CRITICAL9.8⚠ KEVPL ✓ten sam vendor
RCE w Spring Data Commons — podatność property bindera
CVE-2026-47865CRITICAL9.8PL ✓ten sam vendor
VMware Avi Load Balancer — Authentication Bypass w Control Plane
CVE-2026-22752CRITICAL9.6PL ✓ten sam vendor
Authentication Bypass w Spring Security Spring Authorization Server
CVE-2025-22248CRITICAL9.4PL ✓ten sam vendor
Bitnami Pgpool: domyślny dostęp bez uwierzytelnienia przez użytkownika 'repmgr'