>> Linksys WRT54G UPnP AddPortMapping Requests Port Mapping Vulnerability
Title : Linksys WRT54G UPnP AddPortMapping Requests Port Mapping Vulnerability VUPEN ID : VUPEN/ADV-2006-1909 CVE ID : CVE-2006-2559
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-05-22
Technical Description
A vulnerability has been identified in Linksys WRT54G Wireless-G Broadband Router, which could be exploited by attackers to bypass security restrictions. This flaw is due to an error in the UPnP service when handling AddPortMapping requests and the "InternalClient" parameter, which could be exploited by malicious attackers on the local network to forward arbitrary ports from a vulnerable device to a remote host without requiring authentication.