Vulnerabilities
Vulnerable Software
Audiocodes:  >> 420hd Ip Phone  Security Vulnerabilities
An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via shell metacharacters in the query string.
CVSS Score
8.8
EPSS Score
0.195
Published
2019-04-01
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS.
CVSS Score
4.8
EPSS Score
0.002
Published
2019-03-21
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
CVSS Score
8.8
EPSS Score
0.634
Published
2019-03-21


Contact Us

Shodan ® - All rights reserved