PT-2026-60810 · Sangoma · Switchvox Smb Edition+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sangoma Switchvox versions prior to 8.4.0.2
Description
An unauthenticated SQL injection exists in the
/pa endpoint, which processes XML content beginning with <PolycomIPPhone>. The issue occurs because the PhoneIP variable is concatenated directly into PostgreSQL queries without proper sanitization or parameterization. This allows a remote attacker to execute arbitrary SQL statements as a PostgreSQL superuser, which can be further leveraged to achieve remote code execution (RCE) on the underlying operating system. Real-world exploitation has been observed, including the deployment of reverse shells and post-exploitation reconnaissance such as process enumeration. Approximately 4,000 Switchvox systems are estimated to be exposed to the internet, primarily in the United States.Recommendations
Upgrade to version 8.4.0.2 or later.
Restrict access to the
/pa endpoint and the web management interface to trusted IP addresses only to minimize internet exposure.
Inspect /var/log/switchvox/db-quirks.log for unexpected SQL activity and command-execution artifacts.Exploit
Fix
LPE
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Switchvox Smb Edition
Switchvox