CVE-2019-20027: Nec SL1100 Firmware

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.

Affected products

  • Nec SL1100 Firmware: from 7.0
  • Nec SL2100 Firmware: from 7.0
  • Nec SV8100 Firmware: from 7.0
  • Nec SV9100 Firmware: from 7.0

Published 2020-07-29. Last modified 2026-06-17.