ASTPP GitHub Repositoryproduct
https://github.com/iNextrix/ASTPP CVE-2020-37153
HIGH
ASTPP VoIP 4.0.1 - Remote Code Execution
Record summary
CVE-2020-37153 has a selected CVSS score of 7.7 (high); EIP currently links 1 catalogued exploit.
Description
ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ASTPPBrowse ASTPP / ASTPP | CVE List | 4.0.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBASTPP VoIP 4.0.1 - Remote Code ExecutionExploitDB exploitby Fabien AUNAYNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37153 ASTPP Official Vendor Homepageproduct
https://www.astppbilling.org/ ExploitDB-47889exploit
https://www.exploit-db.com/exploits/47889 VulnCheck Advisory: ASTPP VoIP 4.0.1 - Remote Code ExecutionThird-party advisory
https://www.vulncheck.com/advisories/astpp-voip-remote-code-execution