Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/20183 | third party advisory vendor advisory |
http://www.securityview.org/how-does-the-upnp-flaw-works.html | url repurposed |
http://www.vupen.com/english/advisories/2006/1912 | vdb entry |
http://www.securityview.org/dutch-student-finds-a-bug-in-upnp.html | url repurposed |