{ "schema_version": "1.4.0", "id": "GHSA-6583-cq39-w34q", "modified": "2022-05-01T07:00:25Z", "published": "2022-05-01T07:00:25Z", "aliases": [ "CVE-2006-2560" ], "details": "Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2006-2560" }, { "type": "WEB", "url": "http://secunia.com/advisories/20183" }, { "type": "WEB", "url": "http://www.securityview.org/dutch-student-finds-a-bug-in-upnp.html" }, { "type": "WEB", "url": "http://www.securityview.org/how-does-the-upnp-flaw-works.html" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2006/1912" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2006-05-24T01:02:00Z" } }