CVE-2018-5757: Audiocodes 420hd IP Phone Firmware

High severity, CVSS 8.8. EPSS: 7.6% chance of exploitation in the next 30 days.

An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via shell metacharacters in the query string.

Affected products

  • Audiocodes 420hd IP Phone Firmware: version 3.0.0.535.106 only

Published 2019-04-01. Last modified 2026-06-17.