Innovaphone develops a focused line of IP telephony and PBX products where the observed vulnerability footprint clusters around web-interface and authentication layers, including cross-site request forgery, command injection, excessive authentication bypass, and sensitive information exposure. The exposure pattern reflects the administrative interfaces and firmware update mechanisms inherent to telephony control systems; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Innovaphone over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5335MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for reque | Aug 25, 2014 | 6.8 | 34 | NO | YES |
CVE-2022-41870HIGH AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload. | Sep 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2024-24721MEDIUM An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to access | Feb 27, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-24720MEDIUM An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system. | Feb 27, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Innovaphone.
Media articles that mention a CVE ID that affects a product developed by Innovaphone — matched by CVE ID, not by vendor name.