CVE-2016-6255: Debian Linux
High severity, CVSS 7.5. EPSS: 26.6% chance of exploitation in the next 30 days.
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.
Affected products
- Debian Debian Linux: version 8.0 only
- Libupnp Project Libupnp: up to and including 1.6.20
Published 2017-03-07. Last modified 2026-06-17.