PT-2026-67400 · Telenia · Tvox
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Telenia Software TVox versions prior to 26.5.4
Telenia Software TVox versions prior to 24.9.22
Description
Authenticated attackers can execute arbitrary operating system commands with the privileges of the apache user. This occurs in the 'action audio.php' endpoint when the
action parameter is set to 'checkProcess'. The issue stems from the exec() function processing an unsanitized pid parameter, allowing for OS command injection.Recommendations
Update Telenia Software TVox to version 26.5.4 or later.
Update Telenia Software TVox to version 24.9.22 or later.
As a temporary mitigation, restrict access to the 'action audio.php' endpoint or avoid using the
pid parameter when the action is set to 'checkProcess'.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tvox