CallStranger is a flaw in the Open Connectivity Foundation UPnP specification before 2020-04-17. The specification did not prohibit accepting a UPnP event-subscription request when its delivery URL was located on a different network segment from the fully qualified event-subscription URL. In hostapd, the issue manifests as improper handling of UPnP SUBSCRIBE requests when hostapd operates as a WPS access point.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Python-based exploit and verification tool for the CallStranger (CVE-2020-12695) vulnerability in UPnP devices. The main scripts, CallStranger.py and CallDirect.py, discover UPnP devices and services on the local network, then attempt to exploit the vulnerability by sending crafted SUBSCRIBE requests with attacker-controlled CALLBACK headers. The exploit can be used to demonstrate and verify the ability to perform SSRF, bypass DLP, scan internal ports, and participate in DDoS amplification attacks via vulnerable UPnP devices. The tool coordinates with a remote PHP server (CallStranger.php) for vulnerability confirmation, but all sensitive service URLs are encrypted client-side for privacy. The repository includes a modified version of the upnpy library for UPnP communication. Example output files and comprehensive documentation are provided. The exploit is operational and can be used to confirm real-world exposure to this protocol-level vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in hostapd's WPS access-point functionality involving incorrect handling of UPnP SUBSCRIBE requests. The referenced Rocky Linux 8 advisory provides security updates for affected packages.
A remotely reachable vulnerability tracked as CVE-2020-12695, assessed by the referenced Unity Linux advisory as having potentially significant confidentiality and availability impact. The plugin states exploit code is available.
A critical UPnP protocol vulnerability, known as CallStranger, affecting IoT devices including some Epson printers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.