Three Years After Libupnp Bug Was Fixed, Popular Apps and Millions of Devices Still Vulnerable

Advertisement
By Manish Singh | Updated: 4 December 2015 08:41 IST
Three Years After Libupnp Bug Was Fixed, Popular Apps and Millions of Devices Still Vulnerable

Over six million devices continue to remain exposed to remote attacks even though the concerned vulnerabilities had officially been patched around three years ago. Security firm Trend Micro has reported a large number of vulnerable Android apps - including some widely used apps such as Netflix and Tencent QQMusic - are exposing a large pool of devices including smartphones, smart TVs, and routers to the risk of remote code execution attacks.

In December 2012, several vulnerabilities in Portable SDK for UPnP (Universal Plug and Play) devices, or libupnp, a standard set of networking protocols that allow network capable devices such as computers, printers, Wi-Fi access points to seamlessly discover and communicate with each other, were patched. Several mobile apps use these features to play media files or connect to other devices within a user's home network. It has been found that the majority of affected apps continue to use older, compromised SDK versions, making millions of their users vulnerable to attacks.

Trend Micro reports that it has found 547 apps that use older versions of libupnp, crippling the overall security of the app and its users. Of the said number of apps, 326 of them are available on the Google Play Store. The firm hasn't disclosed all the affected apps but noted that Linphone and Tencent QQMusic - that have been since patched - were affected.

The nature of the security holes not only compromises the security of millions of users who use the these apps, but also smartphones and many other network devices that relay the data back and forth. The bug was first publicly reported by security firm Rapid7 nearly three years ago.

Advertisement

The security firm had found programming flaws in common UPnP discovery protocol (SSDP) implementations that allowed an attacker to execute arbitrary code. The firm had also exposed vulnerability in UPnP control interface (SOAP) on private networks, and programming flaws in both. Due to poor configuration, it was found that device functions that should not be allowed to public were left open.

At the time, Rapid7 had warned that many of these network equipment that are no longer being shipped will never receive an update and will likely remain vulnerable forever. It had found vulnerabilities in over 6,900 products made by over 1,500 vendors.

Advertisement

In the blog post, Trend Micro has detailed how these vulnerabilities put smart TVs and other network equipment at security risks too.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco M7 Plus 5G Launched in India With 7,000mAh Battery at This Price
  2. Lenovo Tab Launched in India With 5,100mAh Battery, LTE Connectivity
  3. Google Pixel 10 Series Price in India Reportedly Leaked Ahead of Launch
  4. Realme P4 Series Specifications Confirmed Ahead of Launch on August 20
  5. iPhone 14 Price Drops to an All-Time Low on Vijay Sales
  6. GPT-4o AI Model Is Now Available to All ChatGPT Paid Users
  7. iQOO Z10 Lite 4G With 50-Megapixel Rear Camera Launched: See Price
  8. Best Laptop Offers During the Ongoing Flipkart Freedom Day Sale
  9. FASTag Annual Pass Launches This Independence Day: Here's How to Apply
  10. Perplexity Reportedly Offers to Buy Google Chrome for $34.5 Billion
  1. Google Pixel 10 Series Price in India Reportedly Leaked Ahead of August 20 Launch
  2. Microsoft Edge to Target Heavy Google Chrome Users With More Persuasive Prompts: Report
  3. OpenAI Brings GPT-4o AI Model Back to ChatGPT after User Complaints, Revises GPT-5 Thinking Rate Limits
  4. Lenovo Tab With MediaTek Helio G85 SoC, 5,100mAh Battery Launched in India: Price, Specifications
  5. Poco M7 Plus 5G Launched in India With 7,000mAh Battery, Snapdragon 6s Gen 3 SoC: Price, Specifications
  6. iPhone 14 Price in India Drops to All-Time Low on Vijay Sales: Price, Specifications
  7. Honor Magic V Flip 2 Launch Date Set for August 21; Design, Colour Options Revealed
  8. Google Pixel 10 Pro Fold Design Officially Teased Ahead of Launch on August 20
  9. Perplexity Reportedly Offers to Buy Google Chrome for More Than Its Own Valuation
  10. Raphael Domjan Nears Solar Flight World Record with 8,224-Metre SolarStratos Journey
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.