vendor:
400HD series of IP phones
by:
a.baube at sysdream dot com
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: 400HD series of IP phones
Affected Version From: 2.2.12.126
Affected Version To: 2.2.12.126
Patch Exists: YES
Related CWE: CVE-2018-10093
CPE: h:audiocodes:400hd_series_ip_phones
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: 420HD phone
2018
Remote command injection vulnerability in AudioCode IP phones
The CGI scripts used on the 420HD phone (web interface) do not filter user inputs correctly. Consequently, an authenticated attacker could inject arbitrary commands (Remote Code Execution) and take full control over the device. For example, it is possible to intercept live communications.
Mitigation:
AudioCodes recommends to change the default admin credentials to mitigate the issue.