CVE-2019-12328

CRITICAL

Atcom A10W VoIP <2.6.1a2421 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an authenticated remote attacker in the same network to trigger OS commands via shell metacharacters in a POST request.

References (1)

Core 1
Core References
Exploit, Mitigation, Third Party Advisory x_refsource_misc
https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Atcom_A10W.pdf

Scores

CVSS v3 9.0
EPSS 0.0421
EPSS Percentile 89.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
atcom/a10w_firmware 2.6.1a2421
Published Jul 22, 2019
Tracked Since Feb 18, 2026