Open main menu
Home
Random
Recent changes
Special pages
Community portal
Preferences
About Wikipedia
Disclaimers
Incubator escapee wiki
Search
User menu
Talk
Dark mode
Contributions
Create account
Log in
Editing
Universal Plug and Play
(section)
Warning:
You are not logged in. Your IP address will be publicly visible if you make any edits. If you
log in
or
create an account
, your edits will be attributed to your username, along with other benefits.
Anti-spam check. Do
not
fill this in!
===Callback vulnerability=== On 8 June 2020, yet another protocol design flaw was announced.<ref>{{Cite web|url=https://kb.cert.org/vuls/id/339275|title = CERT/CC Vulnerability Note VU#339275}}</ref> Dubbed "CallStranger"<ref>{{Cite web |url=https://callstranger.com/ |title=CallStranger CVE-2020-12695 |access-date=14 June 2020 |archive-date=16 June 2020 |archive-url=https://web.archive.org/web/20200616122554/https://callstranger.com/ |url-status=dead }}</ref> by its discoverer, it allows an attacker to subvert the event subscription mechanism and execute a variety of attacks: amplification of requests for use in DDoS; enumeration; and data exfiltration. OCF had published a fix to the protocol specification in April 2020,<ref>{{Cite web|url=https://openconnectivity.org/developer/specifications/upnp-resources/upnp/#architectural|title = OCF - UPnP Standards & Architecture}}</ref> but since many devices running UPnP are not easily upgradable, CallStranger is likely to remain a threat for a long time to come.<ref>{{Cite web|url=https://www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of|title = CVE-2020-12695: CallStranger Vulnerability in Universal Plug and Play (UPnP) Puts Billions of Devices at Risk|date = 8 June 2020}}</ref> CallStranger has fueled calls for end-users to abandon UPnP because of repeated failures in security of its design and implementation.<ref>{{Cite web|title=Disable UPnP on Your Wireless Router Already|url=https://lifehacker.com/disable-upnp-on-your-wireless-router-already-1844012366|access-date=14 June 2020|website=Lifehacker|date=12 June 2020 |language=en-us}}</ref>
Edit summary
(Briefly describe your changes)
By publishing changes, you agree to the
Terms of Use
, and you irrevocably agree to release your contribution under the
CC BY-SA 4.0 License
and the
GFDL
. You agree that a hyperlink or URL is sufficient attribution under the Creative Commons license.
Cancel
Editing help
(opens in new window)