CVE-2019-12326

Publication date

2019-07-22 16:05:13

Family

mitre

State

PUBLISHED

Description

Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.