← back
CVE-2023-20126criticalCWE-306

Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability

62Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.8epss 37%
from disclosure to weapon13 days
Published on NVDMay 4
1st PoC+13d
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.