ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Astpp
Astpp astpp |
|
| Vendors & Products |
Astpp
Astpp astpp |
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation. | |
| Title | ASTPP VoIP 4.0.1 - Remote Code Execution | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T21:49:12.844Z
Reserved: 2026-02-03T16:27:45.309Z
Link: CVE-2020-37153
Updated: 2026-02-11T21:49:10.204Z
Status : Received
Published: 2026-02-11T21:16:08.223
Modified: 2026-02-11T21:16:08.223
Link: CVE-2020-37153
No data.