← Vulnerability feed

Vulnerability record · CVE-2020-12695 · published 8 June 2020

CVE-2020-12695: Ui unifi controller incorrect default permissions vulnerability

Ui · Unifi Controller

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

7.5 CVSS 3.1 High EPSS 15% · top 3.4% CWE-276 · Incorrect default permissions
7.5CVSS 3.1 base score, v2 7.8
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
34References
17 Jun 2026Last modified by NVD

Description

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/158051/CallStranger-UPnP-Vulnerability-Checker.html Third Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2020/06/08/2 Mailing ListThird Party Advisory
https://corelight.blog/2020/06/10/detecting-the-new-callstranger-upnp-vulnerability-with-zeek/ Third Party Advisory
https://github.com/corelight/callstranger-detector Third Party Advisory
https://github.com/yunuscadirci/CallStranger Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00011.html Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00013.html Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/12/msg00017.html Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3SHL4LOFGHJ3DIXSUIQELG Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZDWHKGN3LMGSUEOAAVAMOD Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQEYVY4D7LASH6AI4WK3IK2 Mailing ListThird Party Advisory
https://usn.ubuntu.com/4494-1/ Third Party Advisory
https://www.callstranger.com Broken Link
https://www.debian.org/security/2020/dsa-4806 Third Party Advisory
https://www.debian.org/security/2021/dsa-4898 Third Party Advisory
https://www.kb.cert.org/vuls/id/339275 Third Party AdvisoryUS Government Resource
https://www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of Third Party Advisory
http://packetstormsecurity.com/files/158051/CallStranger-UPnP-Vulnerability-Checker.html Third Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2020/06/08/2 Mailing ListThird Party Advisory
https://corelight.blog/2020/06/10/detecting-the-new-callstranger-upnp-vulnerability-with-zeek/ Third Party Advisory
https://github.com/corelight/callstranger-detector Third Party Advisory
https://github.com/yunuscadirci/CallStranger Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00011.html Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00013.html Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/12/msg00017.html Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3SHL4LOFGHJ3DIXSUIQELG Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZDWHKGN3LMGSUEOAAVAMOD Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQEYVY4D7LASH6AI4WK3IK2 Mailing ListThird Party Advisory
https://usn.ubuntu.com/4494-1/ Third Party Advisory
https://www.callstranger.com Broken Link
https://www.debian.org/security/2020/dsa-4806 Third Party Advisory
https://www.debian.org/security/2021/dsa-4898 Third Party Advisory
https://www.kb.cert.org/vuls/id/339275 Third Party AdvisoryUS Government Resource
https://www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of Third Party Advisory

Track CVE-2020-12695 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2020-12695), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.