Vulnerability record · CVE-2013-0230 · published 31 January 2013
CVE-2013-0230: MiniUPnPd SOAPAction handler stack buffer overflow
MMiniupnp Project · Miniupnpd
MiniUPnPd 1.0 contains a stack-based buffer overflow in the ExecuteSoapAction function of its HTTP SOAPAction handler. A long quoted method string overflows a fixed stack buffer, letting a remote attacker run arbitrary code on the device. Because MiniUPnPd is the UPnP daemon on many routers and embedded gateways, the flaw exposes internet-facing and LAN-facing network devices.
Description
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code, and very high EPSS probability make this an urgent fix despite no KEV listing.
What it is
MiniUPnPd 1.0 contains a stack-based buffer overflow in the ExecuteSoapAction function of its HTTP SOAPAction handler. A long quoted method string overflows a fixed stack buffer, letting a remote attacker run arbitrary code on the device. Because MiniUPnPd is the UPnP daemon on many routers and embedded gateways, the flaw exposes internet-facing and LAN-facing network devices.
Impact
An attacker gains remote code execution with the privileges of the MiniUPnPd process, typically root on embedded devices, allowing full control of the device and any traffic it routes.
Attack surface
Reached over the network through the HTTP service's SOAPAction header; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.69151 (99.3rd percentile) and a public Exploit-DB entry (36839) exists, so working exploit code is publicly available.
What to do
- Patch or upgrade MiniUPnPd past 1.0 to a fixed release, or replace the daemon with a maintained version.
- Disable UPnP on the device if it is not required, or restrict the UPnP/HTTP service to trusted internal interfaces only.
- Block inbound access to the UPnP HTTP port at the network edge and segment IoT/embedded devices from critical networks.
- Apply vendor firmware updates for affected routers and gateways, since the daemon is usually bundled in firmware.
Detection
- Inspect HTTP requests for oversized or malformed SOAPAction headers, especially long quoted method values.
- Monitor for crashes or restarts of the MiniUPnPd process and for unexpected outbound connections from UPnP-enabled devices.
- Alert on UPnP/HTTP traffic from external or untrusted source addresses reaching the device's UPnP port.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-0230 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0230), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.