← Vulnerability feed

Vulnerability record · CVE-2013-0230 · published 31 January 2013

CVE-2013-0230: MiniUPnPd SOAPAction handler stack buffer overflow

MMiniupnp Project · Miniupnpd

MiniUPnPd 1.0 contains a stack-based buffer overflow in the ExecuteSoapAction function of its HTTP SOAPAction handler. A long quoted method string overflows a fixed stack buffer, letting a remote attacker run arbitrary code on the device. Because MiniUPnPd is the UPnP daemon on many routers and embedded gateways, the flaw exposes internet-facing and LAN-facing network devices.

10.0 CVSS 2.0 High EPSS 69% · top 0.7% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code, and very high EPSS probability make this an urgent fix despite no KEV listing.

What it is

MiniUPnPd 1.0 contains a stack-based buffer overflow in the ExecuteSoapAction function of its HTTP SOAPAction handler. A long quoted method string overflows a fixed stack buffer, letting a remote attacker run arbitrary code on the device. Because MiniUPnPd is the UPnP daemon on many routers and embedded gateways, the flaw exposes internet-facing and LAN-facing network devices.

Impact

An attacker gains remote code execution with the privileges of the MiniUPnPd process, typically root on embedded devices, allowing full control of the device and any traffic it routes.

Attack surface

Reached over the network through the HTTP service's SOAPAction header; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.69151 (99.3rd percentile) and a public Exploit-DB entry (36839) exists, so working exploit code is publicly available.

What to do

  • Patch or upgrade MiniUPnPd past 1.0 to a fixed release, or replace the daemon with a maintained version.
  • Disable UPnP on the device if it is not required, or restrict the UPnP/HTTP service to trusted internal interfaces only.
  • Block inbound access to the UPnP HTTP port at the network edge and segment IoT/embedded devices from critical networks.
  • Apply vendor firmware updates for affected routers and gateways, since the daemon is usually bundled in firmware.

Detection

  • Inspect HTTP requests for oversized or malformed SOAPAction headers, especially long quoted method values.
  • Monitor for crashes or restarts of the MiniUPnPd process and for unexpected outbound connections from UPnP-enabled devices.
  • Alert on UPnP/HTTP traffic from external or untrusted source addresses reaching the device's UPnP port.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0230 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-8798Miniupnp project miniupnpd memory buffer overflow vulnerabilityInteger signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspe…EPSS 24%7.8CVE-2017-1000494Miniupnp project miniupnpd memory buffer overflow vulnerabilityUninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Servi…EPSS 0.47%7.8CVE-2013-0229MiniUPnPd SSDP handler buffer over-read crashes serviceThe ProcessSSDPRequest function in minissdp.c in MiniUPnPd before 1.4 mishandles a crafted SSDP request, triggering a buffer over-read that crashes t…EPSS 76%analysed7.8CVE-2013-1461Miniupnp project miniupnpd vulnerabilityThe ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of s…EPSS 2.8%7.8CVE-2013-1462Miniupnp project miniupnpd vulnerabilityInteger signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote atta…EPSS 1.8%7.5CVE-2013-2600Miniupnp project miniupnpd information exposure vulnerabilityMiniUPnPd has information disclosure use of snprintf()EPSS 2.3%7.5CVE-2019-12106Miniupnp project miniupnpd use after free vulnerabilityThe updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vuln…EPSS 2.8%7.5CVE-2019-12108Miniupnp project miniupnpd null pointer dereference vulnerabilityA Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2013-0230), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.