VYPR
Unrated severityNVD Advisory· Published Nov 22, 2011· Updated Apr 29, 2026

CVE-2011-4499

CVE-2011-4499

Description

The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

Affected products

11
  • cpe:2.3:a:cisco:linksys_wrt54g_router_firmware:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cisco:linksys_wrt54g_router_firmware:*:*:*:*:*:*:*:*range: <=4.20.8
    • cpe:2.3:a:cisco:linksys_wrt54g_router_firmware:3.03.9:*:*:*:*:*:*:*
    • cpe:2.3:a:cisco:linksys_wrt54g_router_firmware:4.20.7:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:linksys_wrt54gs_router_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cisco:linksys_wrt54gs_router_firmware:*:*:*:*:*:*:*:*range: <=4.70.6
    • cpe:2.3:a:cisco:linksys_wrt54gs_router_firmware:2.09.1:*:*:*:*:*:*:*
  • Linksys/Wrt54g2 versions
    cpe:2.3:h:linksys:wrt54g:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:h:linksys:wrt54g:*:*:*:*:*:*:*:*
    • cpe:2.3:h:linksys:wrt54g:2.2:*:*:*:*:*:*:*
  • Linksys/Wrt54gs4 versions
    cpe:2.3:h:linksys:wrt54gs:1.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:h:linksys:wrt54gs:1.0:*:*:*:*:*:*:*
    • cpe:2.3:h:linksys:wrt54gs:2.0:*:*:*:*:*:*:*
    • cpe:2.3:h:linksys:wrt54gs:3.0:*:*:*:*:*:*:*
    • cpe:2.3:h:linksys:wrt54gs:4.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.