HomeSecurityUnpatched UPnP-enabled devices are exposed to attacks

Unpatched UPnP-enabled devices are vulnerable to attacks

UPnP

Out-of-date software on UPnP-enabled devices can expose them to attacks aimed at exploiting vulnerabilities found in UPnP libraries, which are used by various servers accessible over the Internet.

Of the 1,648,769 results found using the Shodan search engine for Internet-connected devices, Trend Micro researcher Tony Yang discovered that 35% used the MiniUPnPd UPnP daemon for NAT routers, while about 20% used Broadcom's UPnP library.

The abundance of devices accessible via the Internet that have the Universal Plug and Play (UPnP) feature enabled is very worrying, considering the highly successful attacks on Chromecast adapters, Smart TVs, and Google Home, which used them to play a YouTube video promoting the PewDiePie channel.

“The hackers who used this technology exploited poorly updated servers that had the Universal Plug and Play (UPnP) service enabled, which caused public ports to be forwarded to private devices and exposed to the internet,” says Yang.

UPnP-enabled devices have been hacked on a large scale in the past

While this attack was not malicious and did not attempt to steal data or in any way affect the devices it managed to hack, the story would have been very different if the opposite had happened.

Hackers have used UPnP to abuse these types of devices, with an Akamai study finding that advanced threat actors (APTs) and botnet operators are using tens of thousands of routers with UPnP enabled as proxy servers to hide their true location.

Old firmware comes with exploitable vulnerabilities

As detailed in Trend Micro's research, cameras, printers, NAS devices, smart TVs, and routers that use UPnP for streaming, sharing, and other services are the usual suspects for these security holes, which help potential attackers bypass firewalls and reach their local network.

Trend Micro found that “most devices are still using old versions of UPnP libraries. Old vulnerabilities affecting UPnP libraries are potentially unpatched and leave connected devices vulnerable to attacks.”.

The vast majority of these devices are vulnerable, with at least three different security issues present in various versions of the MiniUPnPd library.

Additionally, 18% of UPnP-enabled devices accessible over the Internet use Windows UPnP Server and about 5% of these have the libupnp library installed.

This collection of devices also has its own set of outdated software versions, which can allow access to an attacker.

To ensure that devices in your home are not left exposed and vulnerable to attacks outside of your local networks, you should disable the UPnP feature where possible and always keep your devices' firmware up to date.

“If a device is suspected to be infected, the device should be rebooted, reset to original factory settings, or replaced entirely,” the Trend Micro researcher.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS