Miniupnp.Free maintains a lightweight UPnP implementation embedded across routers, network devices, and multimedia applications, where its narrow product scope belies broad downstream deployment in internet-connected systems. The recurring vulnerability signals center on NULL-pointer dereferences and unchecked return values in protocol parsing, reflecting the memory-safety and error-handling demands of low-level network code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Miniupnp.Free over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12110HIGH An AddPortMapping Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in upnpredirect.c. | May 15, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-12107HIGH The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snprin | May 15, 2019 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Miniupnp.Free.
Media articles that mention a CVE ID that affects a product developed by Miniupnp.Free — matched by CVE ID, not by vendor name.