peter bassill · operator
$ cve CVE-2009-1048 JSON

CVE-2009-1048

9.8
CRITICAL · CVSS 3.1 · EPSS 6.4% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.37% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-290
On CISA KEVno
Public exploitnone known
Published2009-08-14
Last modified2026-06-16

Affected (10)

VendorProduct
snomsnom 300
snomsnom 300 firmware
snomsnom 320
snomsnom 320 firmware
snomsnom 360
snomsnom 360 firmware
snomsnom 370
snomsnom 370 firmware
snomsnom 820
snomsnom 820 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD