logo

Devices’ UPnP Service Emerges as Key Threat to Home IoT Networks

ID: 1c564e1d-73b7-5e8b-8db6-4ec9d8e74d91

STIX ID: report--1c564e1d-73b7-5e8b-8db6-4ec9d8e74d91

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2019-03-06

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Trend Micro research found many home routers and IoT devices still have UPnP enabled and are running outdated UPnP libraries (notably MiniUPnPd and libupnp), leaving them vulnerable to remote code execution, denial-of-service, and hijacking to form proxies for botnets, spam, or other malicious activity; researchers observed high prevalence of vulnerable devices, cited a prior Chromecast/Google Home hijack, and advise updating firmware, disabling UPnP when unnecessary, and factory-resetting or replacing suspected compromised devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.