Multiple critical vulnerabilities in...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vendor description: AGFEO GmbH & Co. KG is a vendor of telephone systems and other (tele-)communication products like DECT phones, headsets or smart home products as well. ### Business recommendation: The available patches should be installed immediately. SEC Consult recommends not to use this product in a production environment until a thorough security review has been performed by security professionals as there are indications for further security issues. ### Vulnerability overview/description: 1) Unauthenticated access to web services and authentication bypass A web service with multiple scripts for debug purposes is accessible on an unusual port on the device. There is also a script to read files from the filesystem. As the web service runs with root privileges all files on the operating system can be read by an attacker. This only affects the ES 5xx product line, all other vulnerabilities affect both ES 5xx and 6xx. The configuration of the device can be changed and...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息