The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
References
Link | Resource |
---|---|
https://framagit.org/medoc92/npupnp | Third Party Advisory |
http://www.openwall.com/lists/oss-security/2021/04/25/2 | Mailing List Third Party Advisory |
https://www.lesbonscomptes.com/upmpdcli/npupnp-doc/libnpupnp.html | Third Party Advisory |
Configurations
Information
Published : 2021-04-25 12:15
Updated : 2021-05-05 13:11
NVD link : CVE-2021-31718
Mitre link : CVE-2021-31718
JSON object : View
CWE
CWE-346
Origin Validation Error
Products Affected
npupnp_project
- npupnp