CVE-2007-0528

Centrality Communications PA168 <1.54 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-0528. PoCs published by Adrian _pagvac_ Pastor.

AI-analyzed exploit summary This exploit targets a weak session management vulnerability in IP phones using the PA168 chipset, allowing an attacker to bypass authentication and retrieve sensitive information (e.g., passwords, SIP credentials) by repeatedly polling the admin settings page while a superuser session is active.

Description

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

Exploits (1)

exploitdb WORKING POC VERIFIED
by Adrian _pagvac_ Pastor · bashremotehardware
https://www.exploit-db.com/exploits/3189

This exploit targets a weak session management vulnerability in IP phones using the PA168 chipset, allowing an attacker to bypass authentication and retrieve sensitive information (e.g., passwords, SIP credentials) by repeatedly polling the admin settings page while a superuser session is active.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: IP Phones based on Centrality Communications/Aredfox PA168 chipset (e.g., ATCOM AT-320ED, SOYO G668)
No auth needed
Prerequisites: Network access to the target IP phone's web interface · Superuser session must be active on the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23936
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0346
Vendor Advisory x_refsource_misc
http://www.procheckup.com/Vulner_PR0614.php
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/457868/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23919
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/32966
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3189

Scores

EPSS 0.0435
EPSS Percentile 90.0%

Details

Status published
Products (1)
centrality_communications/pa168_chipset < firmware_1.54
Published Jan 26, 2007
Tracked Since Feb 18, 2026