CVE-2019-12326: Akuvox SP-r50p Firmware

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.

Affected products

  • Akuvox SP-r50p Firmware: version 50.0.6.156 only

Published 2019-07-22. Last modified 2026-06-17.