Medium severity6.5NVD Advisory· Published Nov 27, 2018· Updated Jun 17, 2026
CVE-2018-11946
CVE-2018-11946
Description
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, the UPnP daemon should not be running out of box because it enables port forwarding without authentication.
Affected products
2Patches
Vulnerability mechanics
References
2- source.codeaurora.org/quic/qsdk/oss/system/feeds/routing/commit/nvdPatchThird Party Advisory
- www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurora-forum-security-bulletinnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.