Miniupnpd
Vendor:
First CVE: Jan 31, 2013 · Active for 13 years
12
Total CVEs
More Total CVEs than 91% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Miniupnpd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2013
13 years ago
Most Recent CVE
Apr 17, 2026
102 days ago
CVE Severity & Scoring
Miniupnpd12 CVEs
83%
17%
All CVEs353,240 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (8.3%)
Network7 (58.3%)
Unknown4 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High0 (0.0%)
Unknown4 (33.3%)
User Interaction
None8 (66.7%)
Unknown4 (33.3%)
Required0 (0.0%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None7 (58.3%)
Unknown4 (33.3%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0230HIGH Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary c | Jan 31, 2013 | 10.0 | 84 | NO | YES |
CVE-2013-0229HIGH The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafte | Jan 31, 2013 | 7.8 | 82 | NO | YES |
CVE-2017-8798CRITICAL Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact. | May 11, 2017 | 9.8 | 56 | NO | YES |
CVE-2026-5720CRITICAL miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a | Apr 17, 2026 | 9.1 | 31 | NO | NO |
CVE-2013-2600HIGH MiniUPnPd has information disclosure use of snprintf() | Nov 1, 2019 | 7.5 | 26 | NO | NO |
CVE-2019-12111HIGH A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c. | May 15, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-12109HIGH A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port. | May 15, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-12108HIGH A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port. | May 15, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-12106HIGH The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability. | May 15, 2019 | 7.5 | 24 | NO | NO |
CVE-2017-1000494HIGH Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memo | Jan 3, 2018 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
16.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
25.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Miniupnpd
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0 | 1 | 9.8 | 24.0% | 0 | 1 |
| 1.9 | 1 | 9.8 | 24.0% | 0 | 1 |
| 1.8 | 2 | 8.7 | 13.2% | 0 | 1 |
| 1.7 | 1 | 9.8 | 24.0% | 0 | 1 |
| 1.5 | 2 | 8.7 | 13.4% | 0 | 1 |
| 1.4 | 2 | 8.7 | 13.4% | 0 | 1 |
| 1.2 | 1 | 7.8 | 76.4% | 0 | 1 |
| 1.1 | 1 | 7.8 | 76.4% | 0 | 1 |
| 1.0 | 4 | 8.3 | 37.5% | 0 | 2 |