CVE-2019-12324

HIGH

Akuvox R50P <50.0.6.156 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox R50P VoIP phone with firmware 50.0.6.156 allows an authenticated remote attacker in the same network to trigger OS commands via shell metacharacters in a POST request.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0434
EPSS Percentile 90.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
akuvox/sp-r50p_firmware 50.0.6.156
Published Jul 22, 2019
Tracked Since Feb 18, 2026