CVE-2019-14260

HIGH

Alcatel-Lucent Enterprise Deskphone VoIP <1.50.13 - Command Injection

Title source: llm
STIX 2.1

Description

On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change Password interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.

References (1)

Core 1

Scores

CVSS v3 8.0
EPSS 0.0280
EPSS Percentile 84.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
al-enterprise/8008_firmware 1.50.13
Published Aug 01, 2019
Tracked Since Feb 18, 2026