CVE-2016-2364: Fonality
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Affected products
- Fonality Fonality: version 12.6 only; version 12.8 only; version 14.1i only
- Fonality Hud Web: up to and including 1.4.1
Published 2016-06-20. Last modified 2026-06-17.