Three Years After Libupnp Bug Was Fixed, Popular Apps and Millions of Devices Still Vulnerable

Advertisement
By Manish Singh | Updated: 4 December 2015 08:41 IST

Over six million devices continue to remain exposed to remote attacks even though the concerned vulnerabilities had officially been patched around three years ago. Security firm Trend Micro has reported a large number of vulnerable Android apps - including some widely used apps such as Netflix and Tencent QQMusic - are exposing a large pool of devices including smartphones, smart TVs, and routers to the risk of remote code execution attacks.

In December 2012, several vulnerabilities in Portable SDK for UPnP (Universal Plug and Play) devices, or libupnp, a standard set of networking protocols that allow network capable devices such as computers, printers, Wi-Fi access points to seamlessly discover and communicate with each other, were patched. Several mobile apps use these features to play media files or connect to other devices within a user's home network. It has been found that the majority of affected apps continue to use older, compromised SDK versions, making millions of their users vulnerable to attacks.

Advertisement

Trend Micro reports that it has found 547 apps that use older versions of libupnp, crippling the overall security of the app and its users. Of the said number of apps, 326 of them are available on the Google Play Store. The firm hasn't disclosed all the affected apps but noted that Linphone and Tencent QQMusic - that have been since patched - were affected.

The nature of the security holes not only compromises the security of millions of users who use the these apps, but also smartphones and many other network devices that relay the data back and forth. The bug was first publicly reported by security firm Rapid7 nearly three years ago.

Advertisement

The security firm had found programming flaws in common UPnP discovery protocol (SSDP) implementations that allowed an attacker to execute arbitrary code. The firm had also exposed vulnerability in UPnP control interface (SOAP) on private networks, and programming flaws in both. Due to poor configuration, it was found that device functions that should not be allowed to public were left open.

At the time, Rapid7 had warned that many of these network equipment that are no longer being shipped will never receive an update and will likely remain vulnerable forever. It had found vulnerabilities in over 6,900 products made by over 1,500 vendors.

Advertisement

In the blog post, Trend Micro has detailed how these vulnerabilities put smart TVs and other network equipment at security risks too.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 17 Max Debuts With 8,000mAh Battery, Leica-Tuned Cameras: See Price
  2. Oppo Find X9s Review: Almost 'Pro'
  3. Maa Behen OTT Release: When and Where to Watch it Online?
  4. Oppo Enco Air 5 Pro With 12mm Drivers Arrives in India at This Price
  5. Gemini Offers Agentic Design Creation With New Adobe and Canva Connectors
  6. Oppo Find X9s vs Vivo X300 FE vs OnePlus 15: Price and Features Compared
  7. Oppo Find X10 Series Tipped to Launch With Notable Battery Upgrades
  1. Scientists Discover New Fuel-Saving Route to the Moon
  2. Madhu Vidhu OTT Release: Where to Watch, Plot, Cast, IMDb Rating, and More
  3. Maa Behen OTT Release Revealed: When and Where to Watch it Online?
  4. LOL: Last One Laughing Germany Season 7 Out on OTT: Know Where to Watch it Online
  5. Warrant: From the World of Vilangu OTT Release Date: When and Where to Watch it Online?
  6. Xiaomi Clip Open-Ear Earbuds Launched With LHDC 5.0 Audio, Up to 38 Hours Total Battery Life: Price, Specifications
  7. Sathi Leelavathi Now Streaming on SunNXT: Everything You Need to Know About Plot, Cast, and More
  8. Xiaomi Smart Band 10 Pro Launched With 1.74-Inch AMOLED Screen, Up to 21 Days Battery Life: Price, Features
  9. Honor Developing Wide-Foldable Phone With Snapdragon 8 Elite Gen 6 SoC, Tipster Claims
  10. Google’s Gemini Offers Agentic Design Creation With New Adobe and Canva Connectors
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.