Impact
MiniUPnPd versions up to 2.3.11 built with the --strict flag contain a divide‑by‑zero error in the ProcessSSDPData() function. When the daemon receives an SSDP M‑SEARCH message with the MX header set to zero and a known service type, the division by MX triggers a SIGFPE, causing the process to crash. The immediate result is a denial of service for the UPnP Internet Gateway Device service, which can be disruptive to device operation on the local network.
Affected Systems
The vulnerability affects any installation of miniupnpd 2.3.11 or earlier that was compiled with the strict option. The affected vendor is the miniupnp project and the product is miniupnpd. No specific version range beyond 2.3.11 is listed, so all earlier releases meeting the build criteria are potentially impacted.
Risk and Exploitability
The CVSS base score of 7.1 reflects a moderate severity consistent with local network denial of service. The EPSS score is unavailable, but the lack of KEV listing suggests no widespread exploitation yet. Because the attack requires an unauthenticated UDP multicast on the local network, the risk is confined to devices directly reachable by the local segmentation. Nonetheless, any attacker with physical or network access could trigger crashes, and the impact can be significant for devices that rely on UPnP for operation.
OpenCVE Enrichment