ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityview.org/how-does-the-upnp-flaw-works.html | url repurposed |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26710 | vdb entry |
http://secunia.com/advisories/20184 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2006/1910 | vdb entry vendor advisory |
http://www.securityview.org/dutch-student-finds-a-bug-in-upnp.html | url repurposed |