CVE-2018-5757

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
01/04/2019
Last modified:
04/04/2019

Description

An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via shell metacharacters in the query string.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:audiocodes:420hd_ip_phone_firmware:3.0.0.535.106:*:*:*:*:*:*:*
cpe:2.3:h:audiocodes:420hd_ip_phone:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools