Metrics
Affected Vendors & Products
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Atcom
Atcom 100m Ip Phones |
|
| Vendors & Products |
Atcom
Atcom 100m Ip Phones |
Fri, 12 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remote code execution with administrative credentials. | |
| Title | Atcom 2.7.x.x Authenticated Command Injection via Web Configuration CGI | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-12T20:13:23.849Z
Reserved: 2025-12-12T14:01:49.142Z
Link: CVE-2024-58314
Updated: 2025-12-12T20:13:13.635Z
Status : Received
Published: 2025-12-12T20:15:39.327
Modified: 2025-12-12T20:15:39.327
Link: CVE-2024-58314
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:15:56Z