CVE-2013-1461: Miniupnp Project Miniupnpd
High severity, CVSS 7.8. EPSS: 2.8% chance of exploitation in the next 30 days.
The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction header that lacks a # (pound sign) character, a different vulnerability than CVE-2013-0230.
Affected products
- Miniupnp Project Miniupnpd: version 1.0 only
Published 2013-01-31. Last modified 2026-06-16.