peter bassill · operator
$ cve CVE-2007-0528 JSON

CVE-2007-0528 EXPLOIT

9.0
HIGH · CVSS 2.0 · EPSS 4.5% (pctl 91)

Patch early

A public exploit exists.

Description

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

Scoring

CVSS9.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS4.49% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2007-01-26
Last modified2026-06-16

Affected (1)

VendorProduct
centrality communicationspa168 chipset

Public exploits

SourceTitleDate
exploit-dbPA168 Chipset IP Phones - Weak Session Management2007-01-24

References

→ the Explorer  ·  watch your stack  ·  NVD