Three Years After Libupnp Bug Was Fixed, Popular Apps and Millions of Devices Still Vulnerable

Advertisement
By Manish Singh | Updated: 4 December 2015 08:41 IST

Over six million devices continue to remain exposed to remote attacks even though the concerned vulnerabilities had officially been patched around three years ago. Security firm Trend Micro has reported a large number of vulnerable Android apps - including some widely used apps such as Netflix and Tencent QQMusic - are exposing a large pool of devices including smartphones, smart TVs, and routers to the risk of remote code execution attacks.

In December 2012, several vulnerabilities in Portable SDK for UPnP (Universal Plug and Play) devices, or libupnp, a standard set of networking protocols that allow network capable devices such as computers, printers, Wi-Fi access points to seamlessly discover and communicate with each other, were patched. Several mobile apps use these features to play media files or connect to other devices within a user's home network. It has been found that the majority of affected apps continue to use older, compromised SDK versions, making millions of their users vulnerable to attacks.

Advertisement

Trend Micro reports that it has found 547 apps that use older versions of libupnp, crippling the overall security of the app and its users. Of the said number of apps, 326 of them are available on the Google Play Store. The firm hasn't disclosed all the affected apps but noted that Linphone and Tencent QQMusic - that have been since patched - were affected.

The nature of the security holes not only compromises the security of millions of users who use the these apps, but also smartphones and many other network devices that relay the data back and forth. The bug was first publicly reported by security firm Rapid7 nearly three years ago.

Advertisement

The security firm had found programming flaws in common UPnP discovery protocol (SSDP) implementations that allowed an attacker to execute arbitrary code. The firm had also exposed vulnerability in UPnP control interface (SOAP) on private networks, and programming flaws in both. Due to poor configuration, it was found that device functions that should not be allowed to public were left open.

At the time, Rapid7 had warned that many of these network equipment that are no longer being shipped will never receive an update and will likely remain vulnerable forever. It had found vulnerabilities in over 6,900 products made by over 1,500 vendors.

Advertisement

In the blog post, Trend Micro has detailed how these vulnerabilities put smart TVs and other network equipment at security risks too.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  2. Vivo T5 Pro 5G Confirmed to Launch in India Soon With These Features
  3. Here's When the Oppo K15 Pro Series Could Be Launched in India
  4. Vivo X300 Ultra European Price Revealed in New Leak
  5. You Can Now Generate Free AI Videos on Google Vids
  6. OnePlus Nord 6 First Impressions
  7. Google's New Open-Source Model Will Let Users Build AI Agents
  8. Samsung Galaxy S26 FE Geekbench Listing Reveals Benchmark Figures
  9. Artemis 2 Leaves Earth Orbit, Starts Journey Towards the Moon
  1. Samsung Galaxy Z Fold 8, Galaxy Z Flip 8 to Stick With Older M13 OLED Panels: Report
  2. Crypto Hack Losses Drop to $168.6 Million in Q1 2026 Despite Ongoing Risks
  3. Google Vids Will Now Let All Users Generate Veo 3.1 AI Videos for Free, New Features Added
  4. Samsung Galaxy S26 FE Surfaces on Geekbench With Exynos 2500 Chip, Android 17
  5. Realme Teases New Narzo Phone on Amazon, Launch Expected Soon
  6. Oppo K15 Pro Series India Launch Timeline Tipped; Could Arrive With the Same Features as the Chinese Variant
  7. Vivo X300 Ultra Leak Reveals European Pricing; Said to Cost Less Than Expected
  8. Google Introduces Gemma 4 Open-Source AI Model, Enables Building Autonomous Agents
  9. Oppo Find X9s Pro, Find X9 Ultra Key Features, Colour Options Leaked Ahead of April 21 Launch
  10. IMF Says Tokenisation Could Transform Finance but Warns of New Risks
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.