CVE-2017-16778

MEDIUM

Fermax Outdoor Panel - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-16778. PoCs published by breaktoprotect.

AI-analyzed exploit summary This repository documents CVE-2017-16778, an authorization bypass vulnerability in Fermax intercom systems via DTMF tone injection. The attack involves playing specific DTMF tones ('1' and '#') to bypass physical access controls.

Description

An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level. By design, only a residential unit owner may allow such an access grant. However, due to incorrect access control, an attacker could inject it via the speaker unit to perform an access grant to gain unauthorized access, as demonstrated by a loud DTMF tone representing '1' and a long '#' (697 Hz and 1209 Hz, followed by 941 Hz and 1477 Hz).

Exploits (1)

nomisec WRITEUP 22 stars
by breaktoprotect · poc
https://github.com/breaktoprotect/CVE-2017-16778-Intercom-DTMF-Injection

This repository documents CVE-2017-16778, an authorization bypass vulnerability in Fermax intercom systems via DTMF tone injection. The attack involves playing specific DTMF tones ('1' and '#') to bypass physical access controls.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Fermax Outdoor Panel (e.g., FER-VCP-100)
No auth needed
Prerequisites: Physical access to the intercom system · A device capable of playing DTMF tones (e.g., phone or Bluetooth speaker)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 4.6
EPSS 0.0131
EPSS Percentile 80.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-863
Status published
Products (1)
fermax/outdoor_panel_firmware
Published Dec 24, 2019
Tracked Since Feb 18, 2026