CVE-2025-1041: Avaya Call Management System

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.

Affected products

  • Avaya Call Management System: from 18.0.0.1, before 19.2.0.7 (fixed in 19.2.0.7); from 20.0, before 20.0.1.0 (fixed in 20.0.1.0)

Published 2025-06-10. Last modified 2026-06-17.