CVE-2020-12695, known as "CallStranger," is a critical vulnerability in the Open Connectivity Foundation UPnP specification that allows subscription requests to be accepted from different network segments. This flaw impacts a wide range of products from numerous vendors, including Microsoft, Cisco, Dell, and HP. With a CVSS score of 7.5 (HIGH), it presents a significant risk due to its network-based attack vector and high potential for data exfiltration, reflected amplified TCP DDoS attacks, and port scanning, despite requiring high attack complexity. While there is no evidence of active exploitation in the wild or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered substantial community attention and media coverage, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ui:unifi_controller:-:*:*:*:*:*:*:* | ||
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:asus:rt-n11:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:broadcom:adsl:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:canon:selphy_cp1200:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.