Telenia Software TVox是Telenia Software公司的一款VoIP电话系统软件。 Telenia Software TVox 26.5.3及之前的26.x版本和24.9.21及之前的24.x版本存在权限许可和访问控制问题漏洞,该漏洞源于/etc/sudoers.d/telenia中的不安全sudoers配置,允许apache用户免密执行/bin/nice,从而利用其调用任意命令,可能导致具有apache账户访问权限的攻击者以root执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Telenia Software | TVox | 26.0.0≤ 26.5.3 |
affected |
24.0.0≤ 24.9.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Telenia Software | TVox | 26.0.0 ~ 26.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64827 | 9.8 CRITICAL | Telenia TVox 26.5.3 Authentication Bypass via set_env.php |
| CVE-2026-67608 | 7.2 HIGH | Telenia TVox 26.5.3 OS Command Injection via action_audio.php |
No comments yet