Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-3010

99
FAUCET Score

CVE-2007-3010 describes a critical command injection vulnerability in the masterCGI component of the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier. This flaw allows unauthenticated remote attackers to execute arbitrary commands on the affected server by injecting shell metacharacters into the 'user' parameter during a ping action. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 100/100, this vulnerability poses a severe threat due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog and recent media coverage. Numerous exploit intelligence sources, including Metasploit modules and Nuclei templates, provide readily available exploit code, indicating a high likelihood of successful exploitation. The vulnerability has garnered significant community attention with 11 mentions, placing it in the top 1% of all CVEs for discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 7.1CPE matchmatch criteria
cpe:2.3:a:al-enterprise:omnipcx_enterprise_communication_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
97.76%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Apr 15, 2022
Metasploit: Alcatel-Lucent OmniPCX Enterprise masterCGI Arbitrary Command Execution · Sep 9, 2007
Nuclei: CVE-2007-3010 · Oct 13, 2023
ExploitDB: EDB-16857 · Oct 5, 2010
This CVE's current EPSS score of 0.9776 is in the 99th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
marc.info
ExploitMailing List
osvdb.org / 40521
Broken Link
secunia.com / advisories/26853
Broken LinkVendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/36632
Third Party AdvisoryVDB Entry
www1.alcatel-lucent.com / psirt/statements/2007002/OXEUMT.htm
Broken Link
redteam-pentesting.de / advisories/rt-sa-2007-001.php
Broken Link
securityfocus.com / archive/1/479699/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/25694
Broken LinkThird Party AdvisoryVDB Entry
vupen.com / english/advisories/2007/3185
Broken Link