Three Years After Libupnp Bug Was Fixed, Popular Apps and Millions of Devices Still Vulnerable

Advertisement
By Manish Singh | Updated: 4 December 2015 08:41 IST

Over six million devices continue to remain exposed to remote attacks even though the concerned vulnerabilities had officially been patched around three years ago. Security firm Trend Micro has reported a large number of vulnerable Android apps - including some widely used apps such as Netflix and Tencent QQMusic - are exposing a large pool of devices including smartphones, smart TVs, and routers to the risk of remote code execution attacks.

In December 2012, several vulnerabilities in Portable SDK for UPnP (Universal Plug and Play) devices, or libupnp, a standard set of networking protocols that allow network capable devices such as computers, printers, Wi-Fi access points to seamlessly discover and communicate with each other, were patched. Several mobile apps use these features to play media files or connect to other devices within a user's home network. It has been found that the majority of affected apps continue to use older, compromised SDK versions, making millions of their users vulnerable to attacks.

Trend Micro reports that it has found 547 apps that use older versions of libupnp, crippling the overall security of the app and its users. Of the said number of apps, 326 of them are available on the Google Play Store. The firm hasn't disclosed all the affected apps but noted that Linphone and Tencent QQMusic - that have been since patched - were affected.

Advertisement

The nature of the security holes not only compromises the security of millions of users who use the these apps, but also smartphones and many other network devices that relay the data back and forth. The bug was first publicly reported by security firm Rapid7 nearly three years ago.

The security firm had found programming flaws in common UPnP discovery protocol (SSDP) implementations that allowed an attacker to execute arbitrary code. The firm had also exposed vulnerability in UPnP control interface (SOAP) on private networks, and programming flaws in both. Due to poor configuration, it was found that device functions that should not be allowed to public were left open.

At the time, Rapid7 had warned that many of these network equipment that are no longer being shipped will never receive an update and will likely remain vulnerable forever. It had found vulnerabilities in over 6,900 products made by over 1,500 vendors.

Advertisement

In the blog post, Trend Micro has detailed how these vulnerabilities put smart TVs and other network equipment at security risks too.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy Tab A11+ With 7,040mAh Battery Launched
  2. Oppo A6 5G With 7,000mAh Battery Launched: Check Price, Features
  3. Amazon Sale 2025: Here are the Best Deals on Smart Bulbs
  4. Apple Fixes Bluetooth, Cellular and Other Issues With Latest Update
  5. Firefly Aerospace's Alpha Rocket Explodes During Ground Preflight Test
  6. iPhone 17 Pro Max Review: A Supercar Engine in Your Pocket
  1. Expedition 73 Astronauts Conduct Physics Experiments, Health Research, and Tech Tests on ISS
  2. Scientists May Finally Explain Mysterious Crown-Like Features on Venus
  3. Firefly Aerospace’s Alpha Rocket Explodes During Ground Preflight Test
  4. Lightweight AI Framework Boosts Speed and Accuracy of UAV Remote Sensing Object Detection
  5. Bridgerton Season 4 OTT Release Revealed: Know Everything About Plot, Streaming Platform, Cast, and More
  6. 13th OTT Release Date Revealed: Know Everything About This Drama Series
  7. Madharaasi OTT Release Date: When and Where to Watch To Stream Sivakarthikeyan Starrer Online
  8. Pawan Kalyan’s They Call Him OG OTT Release Reportedly Revealed: What You Need to Know
  9. Priyanka Kumar’s Doora Theera Yaana Now Streaming on SunNXT: Cast, Plot, and Reception
  10. Jay Kelly OTT Release Date: When and Where to Watch This George Clooney Starrer Movie
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.