CVE-2020-12695 log

Severity Medium
Remote Yes
Type Proxy injection
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. This issue could allow a device connected to the local network (i.e., a device that has been authorized to transmit packets in the network in which the AP is located) to trigger the AP to initiate a HTTP (TCP/IP) connection to an arbitrary URL, including connections to servers in external networks.
Group Package Affected Fixed Severity Status Ticket
AVG-1322 hostapd 2.9-3 2.9-4 Medium Fixed FS#68861
Date Advisory Group Package Severity Type
09 Dec 2020 ASA-202012-16 AVG-1322 hostapd Medium proxy injection