Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
akuvox vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2023-0348
Akuvox E11 allows direct SIP calls. No access control is enforced by the SIP servers, which could allow an malicious user to contact any device within Akuvox to call any other device.
Akuvox E11 Firmware -
6.5
CVSSv3
CVE-2023-0350
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an malicious user to upload a file to the device by changing the extension of a malicious file to an accepted file type.
Akuvox E11 Firmware -
9.8
CVSSv3
CVE-2023-0353
Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypted passwords to be decrypted from the configuration file.
Akuvox E11 Firmware -
9.8
CVSSv3
CVE-2021-31726
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).
Akuvox C315 Firmware 115.116.2613
9.8
CVSSv3
CVE-2019-12326
Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an malicious user to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.
Akuvox Sp-r50p Firmware 50.0.6.156
7.2
CVSSv3
CVE-2019-12324
A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox R50P VoIP phone with firmware 50.0.6.156 allows an authenticated remote attacker in the same network to trigger OS commands via she...
Akuvox Sp-r50p Firmware 50.0.6.156
9.8
CVSSv3
CVE-2019-12327
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an malicious user to get access to the device via telnet. The telnet service is running on port 2323; it cannot be turned off and the credentials cannot be changed.
Akuvox Sp-r50p Firmware 50.0.6.156
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2