CVE-2016-6255
HIGH EXPLOITEDPortable UPnP SDK <1.6.21 - Code Injection
Title source: llmDescription
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.
Exploits (2)
exploitdb
WORKING POC
by Jacob Baines · htmlremotehardware
https://www.exploit-db.com/exploits/40589
Scores
CVSS v3
7.5
EPSS
0.5409
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
VulnCheck KEV
2019-06-13
CWE
CWE-284
Status
published
Products (2)
debian/debian_linux
8.0
libupnp_project/libupnp
< 1.6.20
Published
Mar 07, 2017
Tracked Since
Feb 18, 2026