CVE-2019-7632: Lifesize Networker 220 Firmware

High severity, CVSS 8.8. EPSS: 6.5% chance of exploitation in the next 30 days.

LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter. The lifesize default password for the cli account may sometimes be used for authentication.

Affected products

  • Lifesize Networker 220 Firmware: affected versions not specified
  • Lifesize Passport 220 Firmware: affected versions not specified
  • Lifesize Room 220 Firmware: affected versions not specified
  • Lifesize Team 220 Firmware: affected versions not specified

Published 2019-02-08. Last modified 2026-06-17.