CVE-2020-12695

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/06/2020
Last modified:
08/04/2024

Description

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ui:unifi_controller:-:*:*:*:*:*:*:*
cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* 2.0.0 (excluding)
cpe:2.3:h:asus:rt-n11:-:*:*:*:*:*:*:*
cpe:2.3:h:broadcom:adsl:-:*:*:*:*:*:*:*
cpe:2.3:h:canon:selphy_cp1200:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:wap131:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:wap150:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:wap351:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dvg-n5412sp:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:b1165nfw:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:ep-101:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:ew-m970a3t:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:m571t:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:xp-100:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:xp-2101:-:*:*:*:*:*:*:*