CVE-2026-107159: MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header
MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a single multicast M-SEARCH datagram with MX: 0 and a known ST to port 1900, triggering SIGFPE and denying UPnP IGD service.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects MiniUPnPd versions through 2.3.11 when the daemon was built with the --strict option. The provided information does not establish whether --strict is enabled by default.
Does exploitation require authentication or user interaction?
No. An unauthenticated attacker on the local network can trigger the condition without user interaction.
What network access and request details are needed to exploit this?
The attacker needs local-network access and must send a single multicast SSDP M-SEARCH datagram to port 1900 with an MX value of 0 and a known ST value.
What evidence would indicate an exploitation attempt or impact?
Successful exploitation causes a divide-by-zero condition in ProcessSSDPData() that triggers SIGFPE and crashes the daemon, denying UPnP IGD service.