vendor:
IP Phone
by:
Mohammed Adel
8.1
CVSS
CRITICAL
Authenticated Command Injection
78
CWE
Product Name: IP Phone
Affected Version From: 2.7.x.x
Affected Version To: All versions above 2.7.x.x
Patch Exists: NO
Related CWE:
CPE: a:atcom:ip_phone:2.7.x.x
Platforms Tested: Kali Linux
2023
Atcom 2.7.x.x – Authenticated Command Injection
The Atcom 2.7.x.x version is vulnerable to an authenticated command injection vulnerability. By sending a specially crafted request to the web_cgi_main.cgi script, an attacker can inject arbitrary commands into the system. This can lead to remote code execution and unauthorized access to the target system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the software. Additionally, it is advised to restrict access to the affected endpoint and implement proper access controls.