CVE-2018-11641: Dialogic Powermedia Xms
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service.
Affected products
- Dialogic Powermedia Xms: up to and including 3.5
Published 2018-07-03. Last modified 2026-06-17.