ID:11009 - Exploit for Missing Authentication for Critical Function in SPA112 2-Port Phone Adapter - CVE-2023-20126

 
Main Vulnerability Database Exploits ID:11009 - Exploit for Missing Authentication for Critical Function in SPA112 2-Port Phone Adapter - CVE-2023-20126

ID:11009 - Exploit for Missing Authentication for Critical Function in SPA112 2-Port Phone Adapter - CVE-2023-20126

Published: December 19, 2024


Vulnerability identifier: #VU75708
Vulnerability risk: Critical
CVE-ID: CVE-2023-20126
CWE-ID: CWE-306
Exploitation vector: Remote access
Vulnerable software:
SPA112 2-Port Phone Adapter

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected device.

The vulnerability exists due to missing authentication within the firmware upgrade function. A remote attacker can upgrade the affected device with a specially crafted firmware and gain full control over it.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.