CVE-2019-20027: Nec SL1100 Firmware
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.
Affected products
- Nec SL1100 Firmware: from 7.0
- Nec SL2100 Firmware: from 7.0
- Nec SV8100 Firmware: from 7.0
- Nec SV9100 Firmware: from 7.0
Published 2020-07-29. Last modified 2026-06-17.