CVE-2019-14259

HIGH

Polycom Obihai Obi1022 VoIP <5.1.11 - Command Injection

Title source: llm
STIX 2.1

Description

On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.

References (1)

Core 1
Core References

Scores

CVSS v3 8.0
EPSS 0.0280
EPSS Percentile 84.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
polycom/obihai_obi1022_firmware 5.1.11
Published Aug 01, 2019
Tracked Since Feb 18, 2026