Vulnerability record · CVE-2018-10093 · published 21 March 2019
CVE-2018-10093: AudioCodes 420HD IP phone firmware missing authorization enables remote code execution
Audiocodes · 420hd Ip Phone Firmware
AudioCodes 420HD IP phones running firmware 2.2.12.126 contain a missing authorization flaw (CWE-862) that permits remote code execution. The vulnerability is network reachable and requires only low-privileged access, making it a serious risk for exposed VoIP endpoints.
Description
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable remote code execution with public exploits and very high EPSS, but it requires low privileges and is not in KEV.
What it is
AudioCodes 420HD IP phones running firmware 2.2.12.126 contain a missing authorization flaw (CWE-862) that permits remote code execution. The vulnerability is network reachable and requires only low-privileged access, making it a serious risk for exposed VoIP endpoints.
Impact
An attacker with low-privileged access can execute arbitrary code on the phone, gaining full control of confidentiality, integrity and availability of the device.
Attack surface
Reachable over the network via the phone's management interface; the CVSS vector indicates low privileges are required and no user interaction is needed.
Exploitation
Public exploit code exists in Packet Storm, Full Disclosure and Exploit-DB, and EPSS is 0.6819 (99.3rd percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade 420HD firmware beyond 2.2.12.126 to a vendor-supported release
- Restrict network access to the phone management interface to trusted management VLANs or hosts
- Change default administrative credentials and enforce strong authentication
- Monitor vendor advisories for a confirmed fixed firmware version
Detection
- Inspect phone management interface logs for unexpected command execution or configuration changes
- Alert on anomalous outbound connections from IP phone segments
- Monitor for known exploit payload patterns against the 420HD web interface
- Baseline normal phone traffic and flag deviations in request volume or endpoints
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/151116/AudioCode-400HD-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Jan/38 | ExploitMailing ListThird Party Advisory |
| https://www.exploit-db.com/exploits/46164/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/151116/AudioCode-400HD-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/Jan/38 | ExploitMailing ListThird Party Advisory |
| https://www.exploit-db.com/exploits/46164/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-10093 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-10093), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.