CVE-2007-5636

Nortel IP Softphone 2050 - Buffer Overflow via RTCP Port Flood

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5636. PoCs published by Cyrill Brunschwiler.

AI-analyzed exploit summary The provided Java code is a functional proof-of-concept exploit for CVE-2007-5636, targeting a buffer overflow vulnerability in Nortel Networks UNIStim IP Softphone. It sends maliciously crafted UDP packets to trigger the overflow, potentially leading to remote code execution or denial-of-service.

Description

Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute arbitrary code via a flood of invalid characters to the RTCP port (5678/udp) that triggers a Windows error message, aka "extraneous messaging."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cyrill Brunschwiler · javaremotemultiple
https://www.exploit-db.com/exploits/30678

The provided Java code is a functional proof-of-concept exploit for CVE-2007-5636, targeting a buffer overflow vulnerability in Nortel Networks UNIStim IP Softphone. It sends maliciously crafted UDP packets to trigger the overflow, potentially leading to remote code execution or denial-of-service.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nortel Networks UNIStim IP Softphone
No auth needed
Prerequisites: Network access to the target system · Target system running vulnerable Nortel UNIStim IP Softphone
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/482476/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27252
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3271
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3540
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38521
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37256
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26118

Scores

EPSS 0.0669
EPSS Percentile 93.1%

Details

CWE
CWE-119
Status published
Products (1)
nortel/ip_softphone_2050
Published Oct 23, 2007
Tracked Since Feb 18, 2026