Telenia Software TVox是Telenia Software公司的一款VoIP电话系统软件。 Telenia Software TVox 26.5.3及之前的26.x版本和24.9.21及之前的24.x版本存在命令注入漏洞,该漏洞源于action_audio.php文件对pid参数验证不足,攻击者可设置action参数为checkProcess,将未清理的pid参数传入exec()调用,从而注入恶意操作系统命令,以apache用户权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Telenia Software | TVox | 26.0.0≤ 26.5.3 |
affected |
24.0.0≤ 24.9.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Telenia Software | TVox | 26.0.0 ~ 26.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64827 | 9.8 CRITICAL | Telenia TVox 26.5.3 Authentication Bypass via set_env.php |
| CVE-2026-67609 | 7.8 HIGH | Telenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration |
No comments yet