← Vulnerability feed

Vulnerability record · CVE-2012-5958 · published 31 January 2013

CVE-2012-5958: libupnp SSDP parser stack buffer overflow allows remote code execution

LLibupnp Project · Libupnp

The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 contains a stack-based buffer overflow caused by improper handling of a crafted string after a pointer subtraction. A remote, unauthenticated attacker can trigger it with a single UDP packet, and because the overflow is on the stack it can lead to arbitrary code execution on the affected device or service.

10.0 CVSS 2.0 High EPSS 83% · top 0.3% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a UDP packet with a crafted string that is not properly handled after a certain pointer subtraction.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete confidentiality, integrity and availability impact, combined with a very high EPSS score and public exploit references.

What it is

The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 contains a stack-based buffer overflow caused by improper handling of a crafted string after a pointer subtraction. A remote, unauthenticated attacker can trigger it with a single UDP packet, and because the overflow is on the stack it can lead to arbitrary code execution on the affected device or service.

Impact

An attacker gains remote code execution in the context of the process running libupnp, which on embedded devices and UPnP daemons is often privileged. That allows full compromise of the host, including data theft, persistence, and use as a pivot into the network.

Attack surface

Reached over the network via a UDP packet to the SSDP listener, typically port 1900, with no authentication and no user interaction required (CVSS vector AV:N/AC:L/Au:N). Any host that can send UDP to the exposed SSDP service can attempt the attack.

Exploitation

No CISA KEV listing and no ransomware association is recorded, but EPSS is very high (0.832, 99.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. The flaw is old and widely documented, so exploitation in the wild is plausible.

What to do

  • Upgrade libupnp to 1.6.18 or later, or apply the vendor patch referenced in the CERT/CC advisory (VU#922681); patch first.
  • Update firmware on affected embedded devices and routers (D-Link, Cisco and other advisories are referenced) since they bundle libupnp.
  • Disable or block UPnP/SSDP on untrusted interfaces and restrict UDP port 1900 to trusted networks only.
  • Segment IoT and UPnP-enabled devices away from critical systems and the public internet.
  • Where patching is not possible, monitor and rate-limit SSDP traffic to reduce exposure.

Detection

  • Monitor for anomalous or oversized SSDP M-SEARCH/HTTP-like UDP payloads to port 1900 that contain long crafted strings.
  • Alert on crashes or restarts of UPnP daemons and embedded services that process SSDP.
  • Use network IDS signatures for the libupnp unique_service_name overflow and watch for unexpected outbound connections from UPnP devices.
  • Inventory hosts exposing UDP 1900 and verify their libupnp/firmware version against the fixed 1.6.18 baseline.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2013-02/msg00013.html
http://packetstormsecurity.com/files/160242/libupnp-1.6.18-Denial-Of-Service.html
http://pupnp.sourceforge.net/ChangeLog
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130129-upnp
http://tsd.dlink.com.tw/temp/PMD/12879/DSR-500_500N_1000_1000N_A1_Release_Notes_FW_v1.08B77_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12960/DSR-150N_A2_Release_Notes_FW_v1.05B64_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12966/DSR-150_A1_A2_Release_Notes_FW_v1.08B44_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/13039/DSR-250_250N_A1_A2_Release_Notes_FW_v1.08B44_WW_RU.pdf
http://www.debian.org/security/2013/dsa-2614
http://www.debian.org/security/2013/dsa-2615
http://www.kb.cert.org/vuls/id/922681 PatchUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:098
http://www.securityfocus.com/bid/57602 Exploit
https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-pla
https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf
https://community.rapid7.com/servlet/servlet.FileDownload?file=00P1400000cCaFb
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0037
https://www.tenable.com/security/research/tra-2017-10
http://lists.opensuse.org/opensuse-updates/2013-02/msg00013.html
http://packetstormsecurity.com/files/160242/libupnp-1.6.18-Denial-Of-Service.html
http://pupnp.sourceforge.net/ChangeLog
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130129-upnp
http://tsd.dlink.com.tw/temp/PMD/12879/DSR-500_500N_1000_1000N_A1_Release_Notes_FW_v1.08B77_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12960/DSR-150N_A2_Release_Notes_FW_v1.05B64_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12966/DSR-150_A1_A2_Release_Notes_FW_v1.08B44_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/13039/DSR-250_250N_A1_A2_Release_Notes_FW_v1.08B44_WW_RU.pdf
http://www.debian.org/security/2013/dsa-2614
http://www.debian.org/security/2013/dsa-2615
http://www.kb.cert.org/vuls/id/922681 PatchUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:098
http://www.securityfocus.com/bid/57602 Exploit
https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-pla
https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf
https://community.rapid7.com/servlet/servlet.FileDownload?file=00P1400000cCaFb
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0037
https://www.tenable.com/security/research/tra-2017-10

Track CVE-2012-5958 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-5961Libupnp project libupnp memory buffer overflow vulnerabilityStack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka li…EPSS 37%9.8CVE-2016-8863Libupnp project libupnp memory buffer overflow vulnerabilityHeap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attac…EPSS 8.5%7.5CVE-2020-13848Libupnp project libupnp null pointer dereference vulnerabilityPortable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a N…EPSS 3.5%7.5CVE-2016-6255Debian linux improper access control vulnerabilityPortable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registe…EPSS 27%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2012-5958), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.