← Vulnerability feed

Vulnerability record · CVE-2012-5959 · published 31 January 2013

CVE-2012-5959: libupnp SSDP parser stack buffer overflow via long UDN field

PPortable Sdk For Upnp Project · Portable Sdk For Upnp

The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 has a stack-based buffer overflow. A remote attacker can trigger it by sending a UDP packet containing a long UDN (uuid) field inside a string that includes a double colon. Because libupnp is embedded in many devices and applications, the flaw affects a wide range of UPnP-exposed products.

10.0 CVSS 2.0 High EPSS 76% · top 0.5% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a long UDN (aka uuid) field within a string that contains a :: (colon colon) in a UDP packet.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is remotely exploitable without authentication and has a very high EPSS score with public exploit references, though it is not in KEV and requires a vulnerable libupnp build to be exposed.

What it is

The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 has a stack-based buffer overflow. A remote attacker can trigger it by sending a UDP packet containing a long UDN (uuid) field inside a string that includes a double colon. Because libupnp is embedded in many devices and applications, the flaw affects a wide range of UPnP-exposed products.

Impact

Successful exploitation allows remote code execution with the privileges of the UPnP service, giving the attacker full control of the affected process or device. The CVSS 2.0 vector shows complete confidentiality, integrity and availability impact.

Attack surface

The flaw is reached over the network through SSDP UDP traffic, requiring no authentication and no user interaction. Any host that can send a UDP packet to the SSDP listener on the target can attempt the overflow.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.75796, 99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Upgrade libupnp to version 1.6.18 or later, or apply the vendor firmware update for the affected product.
  • If patching is not immediately possible, disable UPnP/SSDP on internet-facing interfaces and restrict UDP 1900 to trusted networks.
  • Block or filter SSDP traffic at network boundaries and segment IoT and UPnP devices away from critical systems.
  • Inventory devices and applications that embed libupnp and confirm their bundled version against the fixed release.
  • Monitor vendor advisories for the specific affected product to obtain the correct patched firmware.

Detection

  • Inspect network traffic for SSDP M-SEARCH or NOTIFY packets containing unusually long UDN or uuid fields, especially strings with a double colon.
  • Alert on malformed or oversized SSDP payloads sent to UDP port 1900 from unexpected sources.
  • Monitor UPnP service processes for crashes, restarts or abnormal child processes that may indicate exploitation attempts.
  • Use IDS/IPS signatures for CVE-2012-5959 and review logs for repeated SSDP packets from a single source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2013-02/msg00013.html
http://pupnp.sourceforge.net/ChangeLog
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130129-upnp
http://tsd.dlink.com.tw/temp/PMD/12879/DSR-500_500N_1000_1000N_A1_Release_Notes_FW_v1.08B77_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12960/DSR-150N_A2_Release_Notes_FW_v1.05B64_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12966/DSR-150_A1_A2_Release_Notes_FW_v1.08B44_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/13039/DSR-250_250N_A1_A2_Release_Notes_FW_v1.08B44_WW_RU.pdf
http://www.debian.org/security/2013/dsa-2614
http://www.debian.org/security/2013/dsa-2615
http://www.kb.cert.org/vuls/id/922681 PatchUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:098
http://www.securityfocus.com/bid/57602 Exploit
https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-pla
https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf
https://community.rapid7.com/servlet/servlet.FileDownload?file=00P1400000cCaFb
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0037
https://www.tenable.com/security/research/tra-2017-10
http://lists.opensuse.org/opensuse-updates/2013-02/msg00013.html
http://pupnp.sourceforge.net/ChangeLog
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130129-upnp
http://tsd.dlink.com.tw/temp/PMD/12879/DSR-500_500N_1000_1000N_A1_Release_Notes_FW_v1.08B77_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12960/DSR-150N_A2_Release_Notes_FW_v1.05B64_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/12966/DSR-150_A1_A2_Release_Notes_FW_v1.08B44_WW.pdf
http://tsd.dlink.com.tw/temp/PMD/13039/DSR-250_250N_A1_A2_Release_Notes_FW_v1.08B44_WW_RU.pdf
http://www.debian.org/security/2013/dsa-2614
http://www.debian.org/security/2013/dsa-2615
http://www.kb.cert.org/vuls/id/922681 PatchUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:098
http://www.securityfocus.com/bid/57602 Exploit
https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-pla
https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf
https://community.rapid7.com/servlet/servlet.FileDownload?file=00P1400000cCaFb
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0037
https://www.tenable.com/security/research/tra-2017-10

Track CVE-2012-5959 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-5960Portable sdk for upnp project portable sdk for upnp memory buffer overflow vulnerabilityStack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka li…EPSS 33%10.0CVE-2012-5962Portable sdk for upnp project portable sdk for upnp memory buffer overflow vulnerabilityStack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka li…EPSS 37%10.0CVE-2012-5963Portable sdk for upnp project portable sdk for upnp memory buffer overflow vulnerabilityStack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka li…EPSS 37%10.0CVE-2012-5964Portable sdk for upnp project portable sdk for upnp memory buffer overflow vulnerabilityStack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka li…EPSS 37%10.0CVE-2012-5965Portable sdk for upnp project portable sdk for upnp memory buffer overflow vulnerabilityStack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka li…EPSS 37%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEVEPSS 1.2%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2012-5959), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.