Impact
A vulnerability exists in the SPON Communications IP Network Audio Device XC‑9603 that allows a remote attacker to manipulate the loadCfg function used to download the configuration file sys_cfg.txt. This flaw results in disclosure of sensitive configuration data, exposing the device’s secure settings and potentially credentialing information. The weakness corresponds to CWE‑200 for information exposure and CWE‑284 for improper authorisation, enabling an attacker to read protected configuration without proper authentication.
Affected Systems
The affected device is the SPON Communications IP Network Audio Device XC‑9603, specifically firmware 1.2.3_20181106 Build 107. No other version information is provided in the vendor or description. The vulnerability applies to the loadCfg component handling sys_cfg.txt.
Risk and Exploitability
The overall CVSS score of 6.9 indicates a medium severity risk, but the lack of access control allows exploitation over the network. EPSS information is unavailable, so the probability of exploitation cannot be quantified, but because the vulnerability is remote and impacts confidentiality, it should not be considered trivial. The device is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet; however, its presence on a network could still facilitate reconnaissance or credential theft.
OpenCVE Enrichment