← Back to browse · API

CVE-2023-20126

Severity
CRITICAL
CVSS
9.8
EPSS
0.36679
Risk score
52.04
CISA KEV
No
PoC
No
Published
2023-05-04
Modified
2024-10-28
First seen
2026-08-07
Aliases
EUVD-2023-24305, GHSA-X7FJ-4595-2PP2
Products
Cisco:Cisco Small Business IP Phones n/a
Sources
euvd EUVD-2023-24305

Description

A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges. Cisco has not released firmware updates to address this vulnerability.

References