Description
A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of the component Configuration File Download. The manipulation results in information disclosure. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-24
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

A vulnerability exists in the SPON Communications IP Network Audio Device XC‑9603 that allows a remote attacker to manipulate the loadCfg function used to download the configuration file sys_cfg.txt. This flaw results in disclosure of sensitive configuration data, exposing the device’s secure settings and potentially credentialing information. The weakness corresponds to CWE‑200 for information exposure and CWE‑284 for improper authorisation, enabling an attacker to read protected configuration without proper authentication.

Affected Systems

The affected device is the SPON Communications IP Network Audio Device XC‑9603, specifically firmware 1.2.3_20181106 Build 107. No other version information is provided in the vendor or description. The vulnerability applies to the loadCfg component handling sys_cfg.txt.

Risk and Exploitability

The overall CVSS score of 6.9 indicates a medium severity risk, but the lack of access control allows exploitation over the network. EPSS information is unavailable, so the probability of exploitation cannot be quantified, but because the vulnerability is remote and impacts confidentiality, it should not be considered trivial. The device is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet; however, its presence on a network could still facilitate reconnaissance or credential theft.

Generated by OpenCVE AI on September 24, 2026 at 02:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released firmware update that addresses the loadCfg information disclosure.
  • Restrict network access to the device so that only authorized management stations can reach the loadCfg endpoint, for example using firewall rules or VLAN segmentation.
  • If a patch is unavailable, disable or block the loadCfg functionality to prevent remote execution of the configuration download routine.

Generated by OpenCVE AI on September 24, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of the component Configuration File Download. The manipulation results in information disclosure. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title SPON Communications IP Network Audio Device XC-9603 Configuration File Download sys_cfg.txt loadCfg information disclosure
First Time appeared Spon Communications
Spon Communications ip Network Audio Device Xc-9603
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:spon_communications:ip_network_audio_device_xc-9603:*:*:*:*:*:*:*:*
Vendors & Products Spon Communications
Spon Communications ip Network Audio Device Xc-9603
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Spon Communications Ip Network Audio Device Xc-9603
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-24T13:16:43.693Z

Reserved: 2026-09-23T16:15:11.535Z

Link: CVE-2026-96774

cve-icon Vulnrichment

Updated: 2026-09-24T13:16:40.319Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T01:17:00.387

Modified: 2026-09-24T14:40:36.103

Link: CVE-2026-96774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T09:09:01Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control