CVE-2020-37153
- EPSS 0.15%
- Veröffentlicht 11.02.2026 20:49:48
- Zuletzt bearbeitet 20.02.2026 20:22:16
ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator session...
CVE-2020-37104
- EPSS 0.15%
- Veröffentlicht 11.02.2026 20:49:47
- Zuletzt bearbeitet 20.02.2026 20:20:52
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup...
CVE-2019-15075
- EPSS 0.09%
- Veröffentlicht 20.03.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:28:00
An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and the r)fddEw232f encryption key.