Atcom 100M IP Phones Command Injection Vulnerability Allowing Remote Code Execution
Vulnerability
A command injection vulnerability has been identified in Atcom 100M IP Phones running firmware version 2.7.x.x. This vulnerability exists in the web configuration CGI script, specifically within the 'cmd' parameter of 'web_cgi_main.cgi'. It allows authenticated attackers to execute arbitrary system commands, leading to remote code execution with administrative privileges.
Impact
Exploitation of this vulnerability allows for authenticated command injection, with the potential for remote code execution on the affected device.
Reproduction
To reproduce this vulnerability, send a POST request to '/cgi-bin/web_cgi_main.cgi?user_get_phone_ping' with an Authorization header that includes Digest authentication for the 'admin' user. The 'cmd' parameter can be used to inject shell commands, which will be executed on the system. The response will include the result of the executed command, encoded in base64.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
