> For the complete documentation index, see [llms.txt](https://jarrettgxz-sec.gitbook.io/penetration-testing-ethical-hacking-concepts/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://jarrettgxz-sec.gitbook.io/penetration-testing-ethical-hacking-concepts/upnp-exploitation/what-is-upnp.md).

# What is UPnP?

What is Universal Plug and Play (UPnP),  and what are the associated vulnerabilities and exploitation?

Universal Plug and Play (or some may call it Universal ***Pwn*** and Play) is a service that allows devices on the same network to discover and interact with each other using standard networking protocols such as TCP and UDP, without any prior configurations.

UPnP can also be utilized to view and modify router configurations, such as the following:

1. Retrieve firewall port mapping configurations
2. Modify firewall port mapping configurations
3. Modify DNS server configurations
4. Terminate connections
