8.8
CVSSv3

CVE-2021-40845

Published: 15/09/2021 Updated: 27/09/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The web part of Zenitel AlphaCom XE Audio Server up to and including 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zenitel alphacom xe audio server

Exploits

Remote command execution exploit for Zenitel AlphaCom XE Audio Server versions up to 112310 which have a web interface called AlphaWeb XE that allows for a remote shell upload ...
Zenitel AlphaCom XE Audio Server versions up to 112310 have a web interface called AlphaWeb XE that allows for a remote shell upload ...

Github Repositories

AlphaWeb XE, the embedded web server running on AlphaCom XE, has a vulnerability which allows to upload PHP files leading to RCE once the authentication is successful - https://ricardojoserf.github.io/CVE-2021-40845/

CVE-2021-40845 I VULNERABILITY AlphaWeb XE - Authenticated Insecure File Upload leading to RCE II CVE REFERENCE CVE-2021-40845 III VENDOR wwwzenitelcom/ IV DESCRIPTION The web part of Zenitel AlphaCom XE Audio Server through 112310, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/indexphp Neither the content nor extensio