← Vulnerability feed

Vulnerability record · CVE-2007-3010 · published 18 September 2007

CVE-2007-3010: Alcatel OmniPCX Enterprise masterCGI command injection via ping user parameter

Al Enterprise · Omnipcx Enterprise Communication Server

The Unified Maintenance Tool's masterCGI in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier passes the user parameter unsanitized into a ping action, allowing shell metacharacter injection. An unauthenticated remote attacker can therefore run arbitrary commands on the server. This is a critical, network-reachable flaw in a telephony/communications platform.

9.8 CVSS 3.1 Critical CISA KEV since 15 Apr 2022 EPSS 97% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 10.0
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
19References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS 9.8, KEV listing, and near-maximum EPSS makes this an urgent patch-or-isolate case.

What it is

The Unified Maintenance Tool's masterCGI in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier passes the user parameter unsanitized into a ping action, allowing shell metacharacter injection. An unauthenticated remote attacker can therefore run arbitrary commands on the server. This is a critical, network-reachable flaw in a telephony/communications platform.

Impact

An attacker gains arbitrary command execution with the privileges of the masterCGI process, enabling full compromise of the communication server. That can lead to data theft, service disruption, or use of the host as a pivot into the voice network.

Attack surface

Reachable over the network via the Unified Maintenance Tool's masterCGI endpoint, specifically the ping action's user parameter. The CVSS vector shows no privileges required and no user interaction, so it is exploitable pre-authentication if the endpoint is exposed.

Exploitation

It is listed in CISA KEV (added 2022-04-15) and has a very high EPSS probability (0.974, ~99.9th percentile), and a public exploit reference exists, indicating active exploitation and reliable weaponization. No ransomware campaign use is documented.

What to do

  • Apply the vendor update per Alcatel instructions; upgrade OmniPCX Enterprise beyond R7.1 or apply the PSIRT-recommended fix.
  • Restrict network access to the Unified Maintenance Tool/masterCGI interface to trusted management networks only.
  • Do not expose the maintenance web interface to the internet or untrusted segments; place it behind a firewall or VPN.
  • If patching is not possible, disable or block the ping action in masterCGI and monitor for parameter tampering.
  • Review and harden the masterCGI service account so command execution has minimal privileges.

Detection

  • Monitor web/proxy logs for requests to masterCGI with shell metacharacters (;, |, `, $(), &&) in the user parameter.
  • Alert on unexpected child processes spawned by the web server or masterCGI, especially ping or shell interpreters.
  • Hunt for outbound connections or command-and-control traffic originating from the OmniPCX server.
  • Audit the Unified Maintenance Tool for unauthorized configuration changes or new accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2007-3010 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-3010 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-3010), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.