Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-29462— DNS rebinding in pupnp

Quick assessment

Affected
pupnp pupnp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

UPnP是Open Connectivity Foundation基金会的一款通用即插即用协议。 UPnP Devices 中的Portable SDK 1.14.6版本及之后版本存在数据伪造问题漏洞,该漏洞源于它不检查“主机”报头的值。

CVSS 7.6 · High EPSS 0.63% · P48
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-29462

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DNS rebinding in pupnp
Source: CVE Program / CVE List V5
Vulnerability Description
The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by using DNS revolvers which block DNS-rebinding attacks. The vulnerability is fixed in version 1.14.6 and later.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
UPnP 数据伪造问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
UPnP是Open Connectivity Foundation基金会的一款通用即插即用协议。 UPnP Devices 中的Portable SDK 1.14.6版本及之后版本存在数据伪造问题漏洞,该漏洞源于它不检查“主机”报头的值。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
pupnp pupnp < 1.14.6 -

II. Public POCs for CVE-2021-29462

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-29462

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-29462 (1)

Mailing List Discussions for CVE-2021-29462 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-29462

No comments yet


Leave a comment