Vulnerability record · CVE-2007-3010 · published 18 September 2007
CVE-2007-3010: Alcatel OmniPCX Enterprise masterCGI command injection via ping user parameter
Al Enterprise · Omnipcx Enterprise Communication Server
The Unified Maintenance Tool's masterCGI in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier passes the user parameter unsanitized into a ping action, allowing shell metacharacter injection. An unauthenticated remote attacker can therefore run arbitrary commands on the server. This is a critical, network-reachable flaw in a telephony/communications platform.
Description
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 9.8, KEV listing, and near-maximum EPSS makes this an urgent patch-or-isolate case.
What it is
The Unified Maintenance Tool's masterCGI in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier passes the user parameter unsanitized into a ping action, allowing shell metacharacter injection. An unauthenticated remote attacker can therefore run arbitrary commands on the server. This is a critical, network-reachable flaw in a telephony/communications platform.
Impact
An attacker gains arbitrary command execution with the privileges of the masterCGI process, enabling full compromise of the communication server. That can lead to data theft, service disruption, or use of the host as a pivot into the voice network.
Attack surface
Reachable over the network via the Unified Maintenance Tool's masterCGI endpoint, specifically the ping action's user parameter. The CVSS vector shows no privileges required and no user interaction, so it is exploitable pre-authentication if the endpoint is exposed.
Exploitation
It is listed in CISA KEV (added 2022-04-15) and has a very high EPSS probability (0.974, ~99.9th percentile), and a public exploit reference exists, indicating active exploitation and reliable weaponization. No ransomware campaign use is documented.
What to do
- Apply the vendor update per Alcatel instructions; upgrade OmniPCX Enterprise beyond R7.1 or apply the PSIRT-recommended fix.
- Restrict network access to the Unified Maintenance Tool/masterCGI interface to trusted management networks only.
- Do not expose the maintenance web interface to the internet or untrusted segments; place it behind a firewall or VPN.
- If patching is not possible, disable or block the ping action in masterCGI and monitor for parameter tampering.
- Review and harden the masterCGI service account so command execution has minimal privileges.
Detection
- Monitor web/proxy logs for requests to masterCGI with shell metacharacters (;, |, `, $(), &&) in the user parameter.
- Alert on unexpected child processes spawned by the web server or masterCGI, especially ping or shell interpreters.
- Hunt for outbound connections or command-and-control traffic originating from the OmniPCX server.
- Audit the Unified Maintenance Tool for unauthorized configuration changes or new accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2007-3010 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3010 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-3010), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.