CVE-2019-20029: Nec SL1100 Firmware

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.

Affected products

  • Nec SL1100 Firmware: any version
  • Nec SL2100 Firmware: any version
  • Nec SV8100 Firmware: any version
  • Nec SV9100 Firmware: any version

Published 2020-07-29. Last modified 2026-06-17.