CVE-2023-20126
CRITICALCisco SPA112 - RCE
Title source: llmDescription
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.
Exploits (1)
nomisec
WORKING POC
24 stars
by fullspectrumdev · poc
https://github.com/fullspectrumdev/RancidCrisco
Scores
CVSS v3
9.8
EPSS
0.7391
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (1)
cisco/spa112_firmware
1.4.1 sr9
Published
May 04, 2023
Tracked Since
Feb 18, 2026