Vulnerability record · CVE-2024-58337 · published 30 December 2025
CVE-2024-58337: Akuvox s539 firmware missing authorization vulnerability
Akuvox · S539 Firmware
Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.
Description
Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cxsecurity.com/issue/WLB-2024110042 | Third Party Advisory |
| https://packetstormsecurity.com/files/182870/ | Broken Link |
| https://www.vulncheck.com/advisories/akuvox-smart-intercom-s-improper-access-control-via-serviceshttpapi | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5862.php | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5862.php | Third Party Advisory |
Track CVE-2024-58337 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-58337), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.