nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58314 CVE-2024-58314
HIGH
Atcom 2.7.x.x Authenticated Command Injection via Web Configuration CGI
Record summary
CVE-2024-58314 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remote code execution with administrative credentials.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
100M IP PhonesBrowse ATCOM Technology co., LTD. / 100M IP PhonesDefault status: unaffected | CVE List | 2.7 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAtcom 2.7.x.x - Authenticated Command InjectionExploitDB exploitby Mohammed AdelNot analyzed1 file
References
4Atcom IP Phone Webpageproduct
https://www.atcom.cn/html/yingwenban/Product/Fast_IP_phone/2017/1023/135.html ExploitDB-51742exploit
https://www.exploit-db.com/exploits/51742 VulnCheck Advisory: Atcom 2.7.x.x Authenticated Command Injection via Web Configuration CGIThird-party advisory
https://www.vulncheck.com/advisories/atcom-xx-authenticated-command-injection-via-web-configuration-cgi