Vulnerability record · CVE-2012-5959 · published 31 January 2013
CVE-2012-5959: libupnp SSDP parser stack buffer overflow via long UDN field
PPortable Sdk For Upnp Project · Portable Sdk For Upnp
The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 has a stack-based buffer overflow. A remote attacker can trigger it by sending a UDP packet containing a long UDN (uuid) field inside a string that includes a double colon. Because libupnp is embedded in many devices and applications, the flaw affects a wide range of UPnP-exposed products.
Description
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a long UDN (aka uuid) field within a string that contains a :: (colon colon) in a UDP packet.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and has a very high EPSS score with public exploit references, though it is not in KEV and requires a vulnerable libupnp build to be exposed.
What it is
The unique_service_name function in the SSDP parser of the portable SDK for UPnP Devices (libupnp) before 1.6.18 has a stack-based buffer overflow. A remote attacker can trigger it by sending a UDP packet containing a long UDN (uuid) field inside a string that includes a double colon. Because libupnp is embedded in many devices and applications, the flaw affects a wide range of UPnP-exposed products.
Impact
Successful exploitation allows remote code execution with the privileges of the UPnP service, giving the attacker full control of the affected process or device. The CVSS 2.0 vector shows complete confidentiality, integrity and availability impact.
Attack surface
The flaw is reached over the network through SSDP UDP traffic, requiring no authentication and no user interaction. Any host that can send a UDP packet to the SSDP listener on the target can attempt the overflow.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high (0.75796, 99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Upgrade libupnp to version 1.6.18 or later, or apply the vendor firmware update for the affected product.
- If patching is not immediately possible, disable UPnP/SSDP on internet-facing interfaces and restrict UDP 1900 to trusted networks.
- Block or filter SSDP traffic at network boundaries and segment IoT and UPnP devices away from critical systems.
- Inventory devices and applications that embed libupnp and confirm their bundled version against the fixed release.
- Monitor vendor advisories for the specific affected product to obtain the correct patched firmware.
Detection
- Inspect network traffic for SSDP M-SEARCH or NOTIFY packets containing unusually long UDN or uuid fields, especially strings with a double colon.
- Alert on malformed or oversized SSDP payloads sent to UDP port 1900 from unexpected sources.
- Monitor UPnP service processes for crashes, restarts or abnormal child processes that may indicate exploitation attempts.
- Use IDS/IPS signatures for CVE-2012-5959 and review logs for repeated SSDP packets from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5959 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5959), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.