← Vulnerability feed

Vulnerability record · CVE-2011-4499 · published 22 November 2011

CVE-2011-4499: Cisco linksys wrt54g router firmware vulnerability

Cisco · Linksys Wrt54g Router Firmware

The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

7.5 CVSS 2.0 High EPSS 1.3% · top 30.5% CWE-16 · CWE-16
7.5CVSS 2.0 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-1247Linksys wrt54g permissions and access controls vulnerabilityThe web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers…EPSS 5.2%10.0CVE-2008-1268Linksys wrt54g improper authentication vulnerabilityThe FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to estab…EPSS 2.5%7.8CVE-2008-1265Linksys wrt54g improper input validation vulnerabilityThe Linksys WRT54G router allows remote attackers to cause a denial of service (device restart) via a long username and password to the FTP interface.EPSS 1.6%7.8CVE-2005-4257Linksys befw11s4 vulnerabilityLinksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destinatio…EPSS 1.4%7.5CVE-2008-1264Linksys wrt54g improper authentication vulnerabilityThe Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a fil…EPSS 3.1%7.5CVE-2006-2559Linksys wrt54g vulnerabilityLinksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP reque…EPSS 1.7%7.5CVE-2005-2799Linksys WRT54G apply.cgi buffer overflow allows remote code executionA buffer overflow exists in apply.cgi on the Linksys WRT54G router (versions 3.01.03, 3.03.6, and possibly others before 4.20.7). A long HTTP POST re…EPSS 71%analysed7.5CVE-2005-2914Linksys wrt54g vulnerabilityezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authenticat…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2011-4499), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.