libupnp's default behavior allows an unauthenticated user access to a server's filesystem through POST and GET requests (CVE-2016-6255).
{ "section": "core" }