miniupnpd is affected by an integer underflow vulnerability in its SOAPAction header parsing functionality that enables remote attackers to trigger denial of service or information disclosure attacks. The flaw stems from improper length validation in the ParseHttpHeaders() function, where a malformed SOAPAction header containing a single quote causes the parsed length to underflow to a large unsigned value when passed to memchr(), resulting in out-of-bounds memory reads that extend far beyond the allocated HTTP request buffer. The vulnerability is remotely exploitable without authentication and can be triggered by sending a specially crafted HTTP request. The attack requires minimal complexity and can cause the vulnerable process to crash or leak sensitive information from adjacent memory regions. While no CVSS vector has been assigned, the FAUCET Risk Score of 37.0/100 and low EPSS score of 0.00063 suggest moderate but not critical severity. The vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild. The vulnerability remains inactive on threat intelligence hot lists, and no public exploit code has been widely distributed. Community attention appears limited at this time, though organizations running miniupnpd should consider applying patches as they become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.10CPE matchmatch criteria | cpe:2.3:a:miniupnp_project:miniupnpd:*:*:*:*:*:*:*:* | ||
>= 0, < 2.3.10CPE match | cpe:2.3:a:miniupnp_project:miniupnpd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.