CVE-2019-20029: Nec SL1100 Firmware
High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.
Affected products
- Nec SL1100 Firmware: any version
- Nec SL2100 Firmware: any version
- Nec SV8100 Firmware: any version
- Nec SV9100 Firmware: any version
Published 2020-07-29. Last modified 2026-06-17.