Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CallStranger — Vulnerability checker for Callstranger (CVE-2020-12695) | Kitploit
Tools/GitHubGitHub/yunuscadirci/callstranger
Vulnerability ScannersIoT SecurityPort ScanningData ExfiltrationNetwork SecurityDNS Analysis
GitHubyunuscadirci/callstranger

CallStranger

Vulnerability checker for Callstranger (CVE-2020-12695)

View Repository
40362195 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CallStranger

This script created by Yunus Çadırcı (https://twitter.com/yunuscadirci) to check against CallStranger (CVE-2020-12695) vulnerability. An attacker can use this vulnerability for:

  • Bypassing DLP for exfiltrating data
  • Using millions of Internet-facing UPnP device as source of amplified reflected TCP DDoS / SYN Flood
  • Scanning internal ports from Internet facing UPnP devices This script only simulates data exfiltration. You can find detailed information on https://www.callstranger.com https://kb.cert.org/vuls/id/339275 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12695 Slightly modified version of https://github.com/5kyc0d3r/upnpy used for base UPnP communication

CallStranger Vulnerability

The CallStranger vulnerability that is found in billions of UPNP devices can be used to exfiltrate data (even if you have proper DLP/border security means) or scan your network or even cause your network to participate in a DDoS attack.
The vulnerability – CallStranger – is caused by Callback header value in UPnP SUBSCRIBE function can be controlled by an attacker and enables an SSRF-like vulnerability which affects millions of Internet facing and billions of LAN devices. This vulnerability can used for

  • Bypassing DLP and network security devices to exfiltrate data
  • Using millions of Internet-facing UPnP device as source of amplified reflected TCP DDoS (not same with https://www.cloudflare.com/learning/ddos/ssdp-ddos-attack/ )
  • Scanning internal ports from Internet facing UPnP devices Possible remediations:
  • Disable unnecessary UPnP services especially for Internet facing devices/interfaces.
  • Check Intranet and server networks to be sure UPnP devices (Routers, IP cameras, printers, media gateways etc.) are not allowing data exfiltration.
  • Make an assessment on network security logs if this vulnerability had been used any threat actor.
  • Contact to ISP/ DDoS protection vendor if their solutions can block traffic generated by UPnP SUBSCRIBE (HTTP NOTIFY) Because this is a protocol vulnerability, it may take a long time for vendors to provide patches. Visit https://callstranger.com and https://kb.cert.org/vuls/id/339275 for detailed information, affected devices, software, and to follow updates. CVE-2020-12695 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12695 is assigned to CallStranger. OCF updated UPnP specification on 17.04.2020 to remediate this vulnerability. Check new specification on https://openconnectivity.org/upnp-specs/UPnP-arch-DeviceArchitecture-v2.0-20200417.pdf

Install

sudo python3 setup.py install

if needed

sudo pip3 install -r requirements.txt

cryptography requests termcolor

Usage

just navigate to CallStranger and run with Python3 (Tested Python 3.7.5 on Windows 10, Python 3.8.2 on Kali 2020.2) For current subnet scan & test:

python3 CallStranger.py

For single device test:

python3 CallDirect.py http://DeviceDocumentPath

example: python3 CallDirect.py http://192.168.1.1:37215/upnpdev.xml

How script works?

  1. Finds all UPnP devices on LAN
  2. Finds all UPnP services
  3. Finds all subscription endpoints
  4. Sends these endpoints as encryted to verification server via UPnP Callback.
  5. Server can't see this endpoints because all encryption is done on client side
  6. Gets encrypted service list from verification server and decrypts on client side
  7. Compares found UPnP services with verified ones

Example Output

Download Tool