Telenia Software TVox是Telenia Software公司的一款VoIP电话系统软件。 Telenia Software TVox 26.5.3及之前的26.x版本和24.9.21及之前的24.x版本存在输入验证错误漏洞,该漏洞源于set_env.php中的redirectToLoginAdminIRequestHaveAccessToken()函数从PHP_SELF获取页面名,在匹配'login_admin.php'时跳过身份验证,导致攻击者可通过附加'/login_admin.p
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Telenia Software | TVox | 26.0.0≤ 26.5.3 |
affected |
24.0.0≤ 24.9.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Telenia Software | TVox | 26.0.0 ~ 26.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67609 | 7.8 HIGH | Telenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration |
| CVE-2026-67608 | 7.2 HIGH | Telenia TVox 26.5.3 OS Command Injection via action_audio.php |
No comments yet