ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Astpp
Astpp astpp |
|
| Vendors & Products |
Astpp
Astpp astpp |
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation. | |
| Title | ASTPP VoIP 4.0.1 - Remote Code Execution | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-11T20:49:48.270Z
Updated: 2026-02-11T21:49:12.844Z
Reserved: 2026-02-03T16:27:45.309Z
Link: CVE-2020-37153
Updated: 2026-02-11T21:49:10.204Z
Status : Awaiting Analysis
Published: 2026-02-11T21:16:08.223
Modified: 2026-02-12T15:10:37.307
Link: CVE-2020-37153
No data.