LiveActive security incident?Get immediate response
CVE Record

CVE-2019-12328: A command injection (missing input validation) issue in the remote phonebook configuration URI in the web i...

A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an authenticated remote attacker in the same network to trigger OS commands via shell metacharacters in a POST request.

CriticalCVSS 9Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

CVE-2019-12328 lets a logged-in attacker on the same network run operating-system commands through the Atcom A10W VoIP phone web interface. The affected firmware named in the sources is 2.6.1a2421. Business urgency is highest where these phones are still deployed on reachable voice or office networks.

Executive priority

Treat as urgent for environments with Atcom A10W phones. A compromised phone can become an internal foothold or disrupt voice services. If affected devices remain in service, prioritize isolation, access restriction, and supported remediation or replacement.

Technical view

The issue is command injection caused by missing input validation in the remote phonebook configuration URI of the Atcom A10W web interface. A low-privileged authenticated attacker on the same network can use shell metacharacters in a POST request to trigger OS commands. CVSS 3.0 is 9.0 with high confidentiality, integrity, and availability impact.

Likely exposure

Exposure is likely limited to organizations still using Atcom A10W phones with firmware 2.6.1a2421 and reachable web management interfaces. The CVSS vector and description indicate same-network access and authentication are required, not unauthenticated internet exploitation.

Exploitation context

The provided bundle does not show CISA KEV listing or other evidence of active exploitation. Exploitability is still serious because only low privileges, no user interaction, and same-network access are required once the phone web interface is reachable.

Researcher notes

The record names a specific firmware and attack surface but provides limited product metadata in the affected field. Avoid broad assumptions beyond Atcom A10W firmware 2.6.1a2421. The public description supports command injection, authenticated access, and same-network reachability requirements.

Mitigation direction

  • Check Atcom or maintainer guidance for fixed firmware or replacement direction.
  • Restrict phone web management access to dedicated administration hosts only.
  • Segment VoIP devices from user workstations and untrusted networks.
  • Remove or rotate unnecessary low-privileged web accounts on affected phones.
  • Prioritize replacement if no supported patched firmware is available.

Validation and detection

  • Inventory Atcom A10W phones and record firmware versions.
  • Confirm whether firmware 2.6.1a2421 is present in production.
  • Map which networks can reach the phone web interface.
  • Review web management accounts for low-privileged access exposure.
  • Check available vendor guidance before planning remediation.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2019-12328 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AC:L/AV:A/A:H/C:H/I:H/PR:L/S:C/UI:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9CVSS 3.0CriticalCVSS:3.0/AC:L/AV:A/A:H/C:H/I:H/PR:L/S:C/UI:N2.36Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

9Critical
CVSS 3.0 vector shape for CVE-2019-12328Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AC:L/AV:A/A:H/C:H/I:H/PR:L/S:C/UI:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.