CVE-2017-18923

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
29/07/2020
Last modified:
05/08/2020

Description

beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:beronet:voice_over_internet_protocol_gateways_firmware:*:*:*:*:*:*:*:* 2.0.0 (including) 3.0.16 (excluding)
cpe:2.3:h:beronet:bf16001e1box:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bf16001t1box:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bf4001e1box:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bf4001t1box:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bf64002e1box:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bf64002t1box:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bfsb1s0:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bfsb2hy:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bfsb2s0:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bfsb2s02xo:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bfsb4xo:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bfsb4xo4xs:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bfsb4xs:-:*:*:*:*:*:*:*
cpe:2.3:h:beronet:bn16fxsfax_b:-:*:*:*:*:*:*:*