ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.
References
| Link | Resource |
|---|---|
| https://github.com/iNextrix/ASTPP | Product |
| https://www.astppbilling.org/ | Product |
| https://www.exploit-db.com/exploits/47889 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/astpp-voip-remote-code-execution | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-02-11 21:16
Updated : 2026-02-20 20:22
NVD link : CVE-2020-37153
Mitre link : CVE-2020-37153
CVE.ORG link : CVE-2020-37153
JSON object : View
Products Affected
inextrix
- astpp
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
