Vulnerability Description
Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Akuvox | Sp-R50P Firmware | 50.0.6.156 |
| Akuvox | Sp-R50P | - |
Related Weaknesses (CWE)
References
- https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Akuvox_R50P.pdfExploitThird Party Advisory
- https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Akuvox_R50P.pdfExploitThird Party Advisory
FAQ
What is CVE-2019-12326?
CVE-2019-12326 is a vulnerability with a CVSS score of 7.2 (HIGH). Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell co...
How severe is CVE-2019-12326?
CVE-2019-12326 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12326?
Check the references section above for vendor advisories and patch information. Affected products include: Akuvox Sp-R50P Firmware, Akuvox Sp-R50P.