Description
MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a single multicast M-SEARCH datagram with MX: 0 and a known ST to port 1900, triggering SIGFPE and denying UPnP IGD service.
Published: 2026-10-07
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

MiniUPnPd versions up to 2.3.11 built with the --strict flag contain a divide‑by‑zero error in the ProcessSSDPData() function. When the daemon receives an SSDP M‑SEARCH message with the MX header set to zero and a known service type, the division by MX triggers a SIGFPE, causing the process to crash. The immediate result is a denial of service for the UPnP Internet Gateway Device service, which can be disruptive to device operation on the local network.

Affected Systems

The vulnerability affects any installation of miniupnpd 2.3.11 or earlier that was compiled with the strict option. The affected vendor is the miniupnp project and the product is miniupnpd. No specific version range beyond 2.3.11 is listed, so all earlier releases meeting the build criteria are potentially impacted.

Risk and Exploitability

The CVSS base score of 7.1 reflects a moderate severity consistent with local network denial of service. The EPSS score is unavailable, but the lack of KEV listing suggests no widespread exploitation yet. Because the attack requires an unauthenticated UDP multicast on the local network, the risk is confined to devices directly reachable by the local segmentation. Nonetheless, any attacker with physical or network access could trigger crashes, and the impact can be significant for devices that rely on UPnP for operation.

Generated by OpenCVE AI on October 7, 2026 at 13:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest version of miniupnpd, or apply the vendor’s patch that removes the divide‑by‑zero check.
  • Configure firewall rules to block or restrict UDP port 1900 traffic from untrusted network segments or hosts.
  • If UPnP is not required, disable the miniupnpd service to eliminate the attack surface.

Generated by OpenCVE AI on October 7, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a single multicast M-SEARCH datagram with MX: 0 and a known ST to port 1900, triggering SIGFPE and denying UPnP IGD service.
Title MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header
First Time appeared Miniupnp Project
Miniupnp Project miniupnpd
Weaknesses CWE-369
CPEs cpe:2.3:a:miniupnp_project:miniupnpd:*:*:*:*:*:*:*:*
Vendors & Products Miniupnp Project
Miniupnp Project miniupnpd
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Miniupnp Project Miniupnpd
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-07T11:59:39.060Z

Reserved: 2026-10-07T10:58:52.326Z

Link: CVE-2026-107159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T12:17:09.283

Modified: 2026-10-07T12:17:09.283

Link: CVE-2026-107159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T13:30:16Z

Weaknesses