Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107159

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Oct 07, 2026
Vendor unknown

Description

MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a single multicast M-SEARCH datagram with MX: 0 and a known ST to port 1900, triggering SIGFPE and denying UPnP IGD service.

References