CVE-2025-0680: New Rock Technologies MX8G Voip Gateway
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.
Affected products
- New Rock Technologies MX8G Voip Gateway: any version
- New Rock Technologies NRP1302/P Desktop IP Phone: any version
- New Rock Technologies OM500 IP-Pbx: any version
Published 2025-01-30. Last modified 2026-06-17.