
Vulnerability checker for Callstranger (CVE-2020-12695)
This script created by Yunus Çadırcı (https://twitter.com/yunuscadirci) to check against CallStranger (CVE-2020-12695) vulnerability. An attacker can use this vulnerability for:
The CallStranger vulnerability that is found in billions of UPNP devices can be used to exfiltrate data (even if you have proper DLP/border security means) or scan your network or even cause your network to participate in a DDoS attack.
The vulnerability – CallStranger – is caused by Callback header value in UPnP SUBSCRIBE function can be controlled by an attacker and enables an SSRF-like vulnerability which affects millions of Internet facing and billions of LAN devices. This vulnerability can used for
sudo python3 setup.py install
if needed
sudo pip3 install -r requirements.txt
cryptography requests termcolor
just navigate to CallStranger and run with Python3 (Tested Python 3.7.5 on Windows 10, Python 3.8.2 on Kali 2020.2) For current subnet scan & test:
python3 CallStranger.py
For single device test:
python3 CallDirect.py http://DeviceDocumentPath
example: python3 CallDirect.py http://192.168.1.1:37215/upnpdev.xml