NULL pointer dereference in PUPnP - #VU151941
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in check_soap_request() in upnp/src/soap/soap_device.c when handling SOAP QueryStateVariable requests containing a text or CDATA node where a varName element is expected. A remote attacker can send a specially crafted HTTP POST request to cause a denial of service.