Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
akuvox vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-0353
Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypted passwords to be decrypted from the configuration file.
Akuvox E11 Firmware -
9.1
CVSSv3
CVE-2023-0354
The Akuvox E11 web server can be accessed without any user authentication, and this could allow an malicious user to access sensitive information, as well as create and download packet captures with known default URLs.
Akuvox E11 Firmware -
7.5
CVSSv3
CVE-2023-0355
Akuvox E11 uses a hard-coded cryptographic key, which could allow an malicious user to decrypt sensitive information.
Akuvox E11 Firmware -
9.8
CVSSv3
CVE-2021-31726
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).
Akuvox C315 Firmware 115.116.2613
7.2
CVSSv3
CVE-2019-12324
A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox R50P VoIP phone with firmware 50.0.6.156 allows an authenticated remote attacker in the same network to trigger OS commands via she...
Akuvox Sp-r50p Firmware 50.0.6.156
9.8
CVSSv3
CVE-2019-12326
Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an malicious user to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.
Akuvox Sp-r50p Firmware 50.0.6.156
9.8
CVSSv3
CVE-2019-12327
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an malicious user to get access to the device via telnet. The telnet service is running on port 2323; it cannot be turned off and the credentials cannot be changed.
Akuvox Sp-r50p Firmware 50.0.6.156
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2