PT-2021-19483 · Akuvox · Akuvox C315

Published

2021-04-25

·

Updated

2021-05-06

·

CVE-2021-31726

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Akuvox C315 version 115.116.2613
Description The issue allows remote command injection via the cfgd server service. The attack vector involves sending a payload to port 189, which is configured to listen on all IP addresses by default (0.0.0.0).
Recommendations For Akuvox C315 version 115.116.2613, consider restricting access to the cfgd server service on port 189 to minimize the risk of exploitation. As a temporary workaround, restrict the service to only listen on specific IP addresses instead of all IP addresses (0.0.0.0) until a patch is available.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31726

Affected Products

Akuvox C315