Three Years After Libupnp Bug Was Fixed, Popular Apps and Millions of Devices Still Vulnerable

Advertisement
By Manish Singh | Updated: 4 December 2015 08:41 IST

Over six million devices continue to remain exposed to remote attacks even though the concerned vulnerabilities had officially been patched around three years ago. Security firm Trend Micro has reported a large number of vulnerable Android apps - including some widely used apps such as Netflix and Tencent QQMusic - are exposing a large pool of devices including smartphones, smart TVs, and routers to the risk of remote code execution attacks.

In December 2012, several vulnerabilities in Portable SDK for UPnP (Universal Plug and Play) devices, or libupnp, a standard set of networking protocols that allow network capable devices such as computers, printers, Wi-Fi access points to seamlessly discover and communicate with each other, were patched. Several mobile apps use these features to play media files or connect to other devices within a user's home network. It has been found that the majority of affected apps continue to use older, compromised SDK versions, making millions of their users vulnerable to attacks.

Trend Micro reports that it has found 547 apps that use older versions of libupnp, crippling the overall security of the app and its users. Of the said number of apps, 326 of them are available on the Google Play Store. The firm hasn't disclosed all the affected apps but noted that Linphone and Tencent QQMusic - that have been since patched - were affected.

Advertisement

The nature of the security holes not only compromises the security of millions of users who use the these apps, but also smartphones and many other network devices that relay the data back and forth. The bug was first publicly reported by security firm Rapid7 nearly three years ago.

Advertisement

The security firm had found programming flaws in common UPnP discovery protocol (SSDP) implementations that allowed an attacker to execute arbitrary code. The firm had also exposed vulnerability in UPnP control interface (SOAP) on private networks, and programming flaws in both. Due to poor configuration, it was found that device functions that should not be allowed to public were left open.

At the time, Rapid7 had warned that many of these network equipment that are no longer being shipped will never receive an update and will likely remain vulnerable forever. It had found vulnerabilities in over 6,900 products made by over 1,500 vendors.

Advertisement

In the blog post, Trend Micro has detailed how these vulnerabilities put smart TVs and other network equipment at security risks too.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series to Launch in These Storage Variants, Colourways
  2. Vivo X300 Series Specs Confirmed, India-Exclusive Red Colour Teased
  3. Vivo X300 Series India Launch Date Announced
  4. Samsung Silently Introduces Galaxy Book 5 Edge 5G With These Features
  5. Which Music Streaming Service is Best for You?
  1. Vivo X300 Series India Launch Date Announced: Here's What to Expect
  2. Redmi Note 15 Series India Launch Timeline Tipped; Redmi 15C Could Debut This Month
  3. Poco Pad M1 May Come With Snapdragon 7s Gen 4 Chip and 12,000mAh Battery; Price Tipped
  4. BSNL Announces Silver Jubilee Prepaid Recharge Plan With 2.5GB of Daily Data and More Benefits
  5. Blue Origin Joins SpaceX in Orbital Booster Reuse Era With New Glenn’s Successful Launch and Landing
  6. AI-Assisted Study Finds No Evidence of Liquid Water in Mars’ Seasonal Dark Streaks
  7. Bison OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  8. Kathleen Madigan: The Family Thread OTT Release Date: When and Where to Watch it Online?
  9. All Her Fault Now Streaming on OTT: Know Where to Watch it Online
  10. Fallout Season 2 OTT Release Date: When and Where to Watch it Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.