CVE-2007-4553

Thomson ST 2030 SIP Phone 1.52.1 - Denial of Service via Malformed Via Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-4553. PoCs published by Humberto J. Abdelnur, MADYNES.

AI-analyzed exploit summary This Perl script exploits a denial-of-service vulnerability in Thomson SpeedTouch 2030 by sending a malformed SIP INVITE message via UDP. The crafted packet causes the device to stop responding, affecting firmware version 1.52.1.

Description

The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Humberto J. Abdelnur · perldoshardware
https://www.exploit-db.com/exploits/30530

This Perl script exploits a denial-of-service vulnerability in Thomson SpeedTouch 2030 by sending a malformed SIP INVITE message via UDP. The crafted packet causes the device to stop responding, affecting firmware version 1.52.1.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Thomson SpeedTouch 2030 firmware 1.52.1
No auth needed
Prerequisites: Network access to the target device · UDP port accessibility
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by MADYNES · perldoshardware
https://www.exploit-db.com/exploits/4319

This exploit sends a malformed SIP INVITE request via UDP to trigger a DoS condition in Thomson 2030 firmware v1.52.1. The payload contains a malformed 'To' header with special characters that cause the device to crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Thomson 2030 firmware v1.52.1
No auth needed
Prerequisites: Network access to the target device · UDP port accessibility
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26587
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25446
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2988
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36217
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3075
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018603

Scores

EPSS 0.0821
EPSS Percentile 94.2%

Details

Status published
Products (1)
thomson/st_2030_sip_phone 1 1.52.1_firmware
Published Aug 28, 2007
Tracked Since Feb 18, 2026