Vulnerability record · CVE-2021-40856 · published 13 December 2021
CVE-2021-40856: Auerswald COMfortel IP phones authentication bypass via path traversal
Auerswald · Comfortel 3600 Ip Firmware
Auerswald COMfortel 1400 IP, 2600 IP and 3600 IP devices before 2.8G allow authentication bypass using the /about/../ substring in a request path. The flaw lets an unauthenticated remote party reach functionality that should require login, exposing device data. The record does not state exactly which resources become reachable beyond the confidentiality impact in the CVSS vector.
Description
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityRemote, unauthenticated bypass with high confidentiality impact, public exploit references and very high EPSS, though not in KEV and limited to confidentiality.
What it is
Auerswald COMfortel 1400 IP, 2600 IP and 3600 IP devices before 2.8G allow authentication bypass using the /about/../ substring in a request path. The flaw lets an unauthenticated remote party reach functionality that should require login, exposing device data. The record does not state exactly which resources become reachable beyond the confidentiality impact in the CVSS vector.
Impact
An attacker gains access to protected device interfaces without credentials, with high confidentiality impact; the CVSS vector shows no integrity or availability impact.
Attack surface
Reachable over the network via crafted HTTP requests containing the /about/../ substring; no authentication and no user interaction are required per the CVSS vector.
Exploitation
Not listed in CISA KEV, but public exploit references exist (Packet Storm and RedTeam Pentesting advisories tagged Exploit) and EPSS is high at roughly 0.50 probability (98.8th percentile).
What to do
- Upgrade COMfortel 1400 IP, 2600 IP and 3600 IP devices to firmware 2.8G or later; the record does not confirm a fixed version beyond 'before 2.8G'.
- If immediate upgrade is not possible, restrict management/web interface access to trusted networks and block external exposure of the device HTTP service.
- Monitor vendor advisories for any backported fix or interim guidance.
- Audit device configurations and logs for unauthorized access attempts using traversal-style paths.
Detection
- Search web/proxy logs for request paths containing '/about/../' or similar traversal sequences against COMfortel devices.
- Alert on unauthenticated access to administrative or configuration endpoints from unexpected source IPs.
- Review device audit logs for sessions that reach protected pages without a preceding successful login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165162/Auerswald-COMfortel-1400-2600-3600-IP-2.8F-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses | ExploitThird Party Advisory |
| https://www.redteam-pentesting.de/en/advisories/rt-sa-2021-004/-auerswald-comfortel-1400-2600-3600-ip-authentication-byp | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/165162/Auerswald-COMfortel-1400-2600-3600-IP-2.8F-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses | ExploitThird Party Advisory |
| https://www.redteam-pentesting.de/en/advisories/rt-sa-2021-004/-auerswald-comfortel-1400-2600-3600-ip-authentication-byp | ExploitThird Party Advisory |
Track CVE-2021-40856 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.