ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.
History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.
Title ASTPP VoIP 4.0.1 - Remote Code Execution
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-11T21:49:12.844Z

Reserved: 2026-02-03T16:27:45.309Z

Link: CVE-2020-37153

cve-icon Vulnrichment

Updated: 2026-02-11T21:49:10.204Z

cve-icon NVD

Status : Received

Published: 2026-02-11T21:16:08.223

Modified: 2026-02-11T21:16:08.223

Link: CVE-2020-37153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.