CVE-2021-40845
HIGHZenitel AlphaCom XE Audio Server <11.2.3.10 - Code Injection
Title source: llmDescription
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.
Exploits (1)
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/164149/Zenitel-AlphaCom-XE-Audio-Server-11.2.3.10-Shell-Upload.html
Exploit, Third Party Advisory x_refsource_misc
https://github.com/ricardojoserf/CVE-2021-40845
Exploit, Third Party Advisory x_refsource_misc
https://ricardojoserf.github.io/CVE-2021-40845/
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/164160/Zenitel-AlphaCom-XE-Audio-Server-11.2.3.10-Shell-Upload.html
Scores
CVSS v3
8.8
EPSS
0.2696
EPSS Percentile
96.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
zenitel/alphacom_xe_audio_server
< 11.2.3.10
Published
Sep 15, 2021
Tracked Since
Feb 18, 2026