vendor:
Atcom IP Phone
by:
Mohammed Adel
6.1
CVSS
HIGH
Command Injection
78
CWE
Product Name: Atcom IP Phone
Affected Version From: 2.7.x.x
Affected Version To: All versions above 2.7.x.x
Patch Exists: NO
Related CWE:
CPE: a:atcom:2.7
Platforms Tested: Kali Linux
2023
Atcom 2.7.x.x – Authenticated Command Injection
The Atcom 2.7.x.x web interface is vulnerable to command injection. An authenticated attacker can execute arbitrary commands by sending a specially crafted request to the web_cgi_main.cgi script.
Mitigation:
Update to a patched version of the software. Avoid exposing the web interface to untrusted networks.