Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T23:17:39.683Z

Reserved: 2019-05-27T00:00:00

Link: CVE-2019-12326

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-22T17:15:38.997

Modified: 2024-11-21T04:22:37.380

Link: CVE-2019-12326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.