CVE-2023-20126 is a critical vulnerability affecting Cisco SPA112 2-Port Phone Adapters, allowing unauthenticated, remote attackers to execute arbitrary code due to a missing authentication process in the firmware upgrade function. This vulnerability has a CVSS score of 9.8 (CRITICAL) and can be exploited with low complexity over the network, leading to full compromise of the device. Although not yet in CISA's KEV catalog, its high EPSS and FAUCET Risk Score indicate significant exploitability potential. Cisco has not released firmware updates, making affected devices permanently vulnerable, and there is community discussion and media coverage highlighting the lack of a fix.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:spa112_firmware:1.4.1:sr9:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.