These people made that infamous UPnP hack using Flash. Granted, it only works with some routers (forget Broadcom based devices, the URLs they use can change per reboot), but it is still a cool hack, that shows that LAN security can be perverted.

This book from Intel Press is currently the only book I know of that describes UPnP in technical detail. The focus is quite on the implementation side instead of the protocol site. Although it is a bit old it is still a valuable research if you want to dig into UPnP.

