Security readout for executives and security teams
Plain-English summary
NCH Axon PBX v2.22 and earlier has a path traversal issue in a log deletion function. A crafted file value can cause deletion outside the intended log path. For executives, the main concern is disruption or loss of application files on affected PBX systems, but severity and exploit prerequisites are not fully documented.
Executive priority
Treat this as a targeted operational risk for any affected PBX instance. Prioritize validation and access restriction, then follow vendor guidance. Escalate if the PBX interface is internet-facing or supports critical telephony operations.
Technical view
The CVE describes path traversal in Axon PBX through the logdelete file parameter. The public record states that v2.22 and earlier are affected. No CVSS, CWE, authentication requirement, patch version, or confirmed exploitation is provided in the supplied sources.
Likely exposure
Exposure is likely limited to organizations running NCH Axon PBX v2.22 or earlier, especially where the PBX web interface or log management functions are reachable by untrusted users or networks.
Exploitation context
A public GitHub reference exists, but the source bundle does not support active exploitation. The CVE is not listed as KEV. Authentication needs, network reachability requirements, and real-world exploitation are not established in the provided evidence.
Researcher notes
The supplied record is sparse: no CVSS, CWE, affected CPEs, authentication details, or patch reference. Analysis should remain constrained to path traversal causing file deletion in Axon PBX v2.22 and earlier.
Mitigation direction
- Check NCH guidance for a fixed release or vendor mitigation.
- Upgrade Axon PBX if NCH provides a corrected version.
- Restrict PBX web access to trusted administrative networks.
- Back up PBX configuration and operational files regularly.
- Limit filesystem permissions for the PBX service account where feasible.
- Monitor for unexpected log deletion or missing application files.
Validation and detection
- Inventory Axon PBX installations and confirm version numbers.
- Identify whether any instance runs v2.22 or earlier.
- Confirm PBX web access is not exposed to the public internet.
- Review logs for unusual log deletion activity or gaps.
- Check file integrity for PBX application and configuration paths.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
File access behavior lookup
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-37441 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/0xfml/poc/blob/main/NCH/Axon_2.22_LFI.mdCVE reference · x_refsource_MISC
- https://www.nch.com.au/pbx/index.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
