Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Miniupnp Project

First CVE: Jan 31, 2013Active for: 13 yearsTotal CVEs: 33
51.8
VTI Score
TOP TARGET

Miniupnp Project maintains a narrowly scoped but widely embedded suite of UPnP protocol libraries and daemons used across networking devices, home automation systems, and embedded applications to facilitate device discovery and port mapping. Despite a small product count, the vendor sits prominently in embedded firmware and network infrastructure, where a single vulnerability can propagate to large numbers of devices with long support horizons. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code; the exposure concentrates in core components such as miniupnpd and miniupnpc and recurs through memory-safety weakness classes including out-of-bounds writes and reads, buffer-boundary violations, and NULL-pointer dereferences that are characteristic of C-based protocol parsers. Defenders should prioritize inventory and updates of devices running affected UPnP libraries, particularly those exposed to untrusted networks, since remediation often depends on manufacturer firmware releases rather than direct patching. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Miniupnp Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2013
13 years ago
Most Recent CVE
Apr 17, 2026
98 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-0230HIGH
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary c
Jan 31, 201310.084NOYES
CVE-2013-0229HIGH
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafte
Jan 31, 20137.882NOYES
CVE-2017-8798CRITICAL
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
May 11, 20179.856NOYES
CVE-2026-5720CRITICAL
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a
Apr 17, 20269.131NONO
CVE-2018-11576CRITICAL
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.
May 31, 20189.828NONO
CVE-2018-11575CRITICAL
ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg.
May 31, 20189.828NONO
CVE-2021-36530HIGH
ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffer without checking the boundary.
Aug 27, 20218.827NONO
CVE-2019-20219HIGH
ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c.
Jan 2, 20208.827NONO
CVE-2018-10717HIGH
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service
May 3, 20188.827NONO
CVE-2021-36531HIGH
ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer without checking the boundary.
Aug 27, 20218.826NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
30%
58%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (21.2%)
Network20 (60.6%)
Unknown6 (18.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (81.8%)
High0 (0.0%)
Unknown6 (18.2%)
User Interaction
None14 (42.4%)
Unknown6 (18.2%)
Required13 (39.4%)
Privileges Required
Low3 (9.1%)
High0 (0.0%)
None24 (72.7%)
Unknown6 (18.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
6.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Miniupnp Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Miniupnp Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Miniupnp Project's Products

View all 4 CNAs →

Top CWEs