Exploits / Vulnerability Discovered : 2019-01-14 |
Type : webapps |
Platform : cgi
This exploit / vulnerability Audiocode 400hd command injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# [CVE-2018-10093] Remote command injection vulnerability in AudioCode IP phones
## Description
The AudioCodes 400HD series of IP phones consists in a range of
easy-to-use, feature-rich desktop devices for the service provider
hosted services, enterprise IP telephony and contact center markets.
The CGI scripts used on the 420HD phone (web interface) do not filter
user inputs correctly. Consequently, an authenticated attacker could
inject arbitrary commands (Remote Code Execution) and take full control
over the device. For example, it is possible to intercept live
communications.