Executive brief
A vulnerability in miniupnpd, a service used by routers to manage network connections, could allow an attacker to crash the service or potentially view sensitive information. By sending a specially crafted network request, an attacker can disrupt internet connectivity management or gain unauthorized access to memory contents. This issue affects devices running older versions of the MiniUPnP daemon.
Technical details
An integer underflow vulnerability exists in the ParseHttpHeaders() function of miniupnpd due to improper length validation when handling SOAPAction headers. When a header contains a single quote without a matching closing quote, the logic that attempts to strip quotes fails to verify the string length is at least two characters. This causes a length variable to underflow to a large unsigned value, which is subsequently passed to memory-scanning functions like memchr(). An attacker can exploit this via a malformed HTTP request to trigger an out-of-bounds read, leading to a process crash (DoS) or potential information disclosure. The issue is fixed in version 2.3.10.
Affected products
- miniupnp project miniupnpd < 2.3.10
Timeline
- 2026-04-17: disclosed
- 2026-04-17: advisory
- 2026-05-04: patched: Patch commit f56bd09b2f2650126b832c5f30a65a09e28167fa