CVE-2024-36440: Swissphone Dical-Red

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is used.

Affected products

Published 2024-08-22. Last modified 2026-06-17.