Many NAT-PMP devices are incorrectly configured, allowing them to field requests received on external network interfaces or map forwarding routes to addresses other than that of the requesting host, making them potentially vulnerable to information disclosure and malicious port mapping requests.
more here.............http://www.kb.cert.org/vuls/id/184540
more here.............http://www.kb.cert.org/vuls/id/184540