CVE-2015-6403: Cisco SPA300 Firmware
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.
Affected products
Published 2015-12-15. Last modified 2026-06-17.