Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26264
HistoryAug 06, 2020 - 9:39 p.m.

Authorization Bypass

2020-08-0621:39:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.005 Low

EPSS

Percentile

77.5%

hostapd is vulnerable to authorization bypass. The vulnerability exists as the Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

References