CVE-2018-16219: Audiocodes 405hd Firmware

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication via a POST request.

Affected products

Published 2019-04-25. Last modified 2026-06-17.