CVE-2016-6255: Debian Linux

High severity, CVSS 7.5. EPSS: 26.6% chance of exploitation in the next 30 days.

Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.

Affected products

Published 2017-03-07. Last modified 2026-06-17.