Logo
vulnerabilityCVE-2026-5720
Name
CVE-2026-5720
Source
NVD ( link)Debian ( link)
Description
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
miniupnpc
Exploitable

Vulnerability Ratings#


7.1
CVSSv4
9.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.2.7
Exploitable
buildroot
master
2.3.3
Exploitable
openwrt
openwrt-25.12
2.2.8-r1
Exploitable