Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-12695

28
FAUCET Score

CVE-2020-12695, known as "CallStranger," is a critical vulnerability in the Open Connectivity Foundation UPnP specification that allows subscription requests to be accepted from different network segments. This flaw impacts a wide range of products from numerous vendors, including Microsoft, Cisco, Dell, and HP. With a CVSS score of 7.5 (HIGH), it presents a significant risk due to its network-based attack vector and high potential for data exfiltration, reflected amplified TCP DDoS attacks, and port scanning, despite requiring high attack complexity. While there is no evidence of active exploitation in the wild or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered substantial community attention and media coverage, indicating its potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:ui:unifi_controller:-:*:*:*:*:*:*:*
< 2.0.0CPE matchmatch criteria
cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:asus:rt-n11:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:broadcom:adsl:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:h:canon:selphy_cp1200:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
15.19%
Probability of exploitation in next 30 days
EPSS Percentile
96.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1519 is in the 80th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gssdp-0:1.0.5-1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gupnp-0:1.0.6-1.el8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: gssdp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: gupnp

Vendor Advisories (1)

redhatCVE-2020-12695Moderate

hostapd: UPnP SUBSCRIBE misbehavior in WPS AP

Jun 8, 2020

References

packetstormsecurity.com / files/158051/CallStranger-UPnP-Vulnerability-Checker.html
Third Party AdvisoryVDB Entry
corelight.blog / 2020/06/10/detecting-the-new-callstranger-upnp-vulnerability-with-zeek
Third Party Advisory
github.com / corelight/callstranger-detector
Third Party Advisory
github.com / yunuscadirci/CallStranger
Third Party Advisory
lists.debian.org / debian-lts-announce/2020/08/msg00011.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2020/08/msg00013.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2020/12/msg00017.html
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/L3SHL4LOFGHJ3DIXSUIQELGVBDJ7V7LB
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MZDWHKGN3LMGSUEOAAVAMOD3IUIPJVOJ
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/RQEYVY4D7LASH6AI4WK3IK2QBFHHF3Q2
Mailing ListThird Party Advisory
usn.ubuntu.com / 4494-1
Third Party Advisory
callstranger.com
Broken Link
debian.org / security/2020/dsa-4806
Third Party Advisory
debian.org / security/2021/dsa-4898
Third Party Advisory
kb.cert.org / vuls/id/339275
Third Party AdvisoryUS Government Resource
tenable.com / blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of
Third Party Advisory
openwall.com / lists/oss-security/2020/06/08/2
Mailing ListThird Party Advisory