Vulnerability record · CVE-2012-5958 · published 31 January 2013
CVE-2012-5958: libupnp SSDP parser stack buffer overflow allows remote code execution
LLibupnp Project · Libupnp
The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 contains a stack-based buffer overflow caused by improper handling of a crafted string after a pointer subtraction. A remote, unauthenticated attacker can trigger it with a single UDP packet, and because the overflow is on the stack it can lead to arbitrary code execution on the affected device or service.
Description
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a UDP packet with a crafted string that is not properly handled after a certain pointer subtraction.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete confidentiality, integrity and availability impact, combined with a very high EPSS score and public exploit references.
What it is
The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 contains a stack-based buffer overflow caused by improper handling of a crafted string after a pointer subtraction. A remote, unauthenticated attacker can trigger it with a single UDP packet, and because the overflow is on the stack it can lead to arbitrary code execution on the affected device or service.
Impact
An attacker gains remote code execution in the context of the process running libupnp, which on embedded devices and UPnP daemons is often privileged. That allows full compromise of the host, including data theft, persistence, and use as a pivot into the network.
Attack surface
Reached over the network via a UDP packet to the SSDP listener, typically port 1900, with no authentication and no user interaction required (CVSS vector AV:N/AC:L/Au:N). Any host that can send UDP to the exposed SSDP service can attempt the attack.
Exploitation
No CISA KEV listing and no ransomware association is recorded, but EPSS is very high (0.832, 99.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. The flaw is old and widely documented, so exploitation in the wild is plausible.
What to do
- Upgrade libupnp to 1.6.18 or later, or apply the vendor patch referenced in the CERT/CC advisory (VU#922681); patch first.
- Update firmware on affected embedded devices and routers (D-Link, Cisco and other advisories are referenced) since they bundle libupnp.
- Disable or block UPnP/SSDP on untrusted interfaces and restrict UDP port 1900 to trusted networks only.
- Segment IoT and UPnP-enabled devices away from critical systems and the public internet.
- Where patching is not possible, monitor and rate-limit SSDP traffic to reduce exposure.
Detection
- Monitor for anomalous or oversized SSDP M-SEARCH/HTTP-like UDP payloads to port 1900 that contain long crafted strings.
- Alert on crashes or restarts of UPnP daemons and embedded services that process SSDP.
- Use network IDS signatures for the libupnp unique_service_name overflow and watch for unexpected outbound connections from UPnP devices.
- Inventory hosts exposing UDP 1900 and verify their libupnp/firmware version against the fixed 1.6.18 baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5958 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5958), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.