← Vulnerability feed

Vulnerability record · CVE-2021-40856 · published 13 December 2021

CVE-2021-40856: Auerswald COMfortel IP phones authentication bypass via path traversal

Auerswald · Comfortel 3600 Ip Firmware

Auerswald COMfortel 1400 IP, 2600 IP and 3600 IP devices before 2.8G allow authentication bypass using the /about/../ substring in a request path. The flaw lets an unauthenticated remote party reach functionality that should require login, exposing device data. The record does not state exactly which resources become reachable beyond the confidentiality impact in the CVSS vector.

7.5 CVSS 3.1 High EPSS 50% · top 1.1% CWE-706 · CWE-706
7.5CVSS 3.1 base score, v2 5.0
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated bypass with high confidentiality impact, public exploit references and very high EPSS, though not in KEV and limited to confidentiality.

What it is

Auerswald COMfortel 1400 IP, 2600 IP and 3600 IP devices before 2.8G allow authentication bypass using the /about/../ substring in a request path. The flaw lets an unauthenticated remote party reach functionality that should require login, exposing device data. The record does not state exactly which resources become reachable beyond the confidentiality impact in the CVSS vector.

Impact

An attacker gains access to protected device interfaces without credentials, with high confidentiality impact; the CVSS vector shows no integrity or availability impact.

Attack surface

Reachable over the network via crafted HTTP requests containing the /about/../ substring; no authentication and no user interaction are required per the CVSS vector.

Exploitation

Not listed in CISA KEV, but public exploit references exist (Packet Storm and RedTeam Pentesting advisories tagged Exploit) and EPSS is high at roughly 0.50 probability (98.8th percentile).

What to do

  • Upgrade COMfortel 1400 IP, 2600 IP and 3600 IP devices to firmware 2.8G or later; the record does not confirm a fixed version beyond 'before 2.8G'.
  • If immediate upgrade is not possible, restrict management/web interface access to trusted networks and block external exposure of the device HTTP service.
  • Monitor vendor advisories for any backported fix or interim guidance.
  • Audit device configurations and logs for unauthorized access attempts using traversal-style paths.

Detection

  • Search web/proxy logs for request paths containing '/about/../' or similar traversal sequences against COMfortel devices.
  • Alert on unauthenticated access to administrative or configuration endpoints from unexpected source IPs.
  • Review device audit logs for sessions that reach protected pages without a preceding successful login.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40856 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2021-40856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.