Executive brief
Linknat VOS3000 and VOS2009 are VoIP softswitch platforms used by telecommunications providers to manage call routing and billing. A critical security flaw allows unauthorized attackers to gain full access to the underlying database without needing a username or password. This could lead to the theft of sensitive customer data, exposure of plaintext credentials, and complete disruption of telecommunications services.
Technical details
An unauthenticated SQL injection vulnerability exists in the login.jsp component of Linknat VOS3000 and VOS2009. The flaw is rooted in the improper neutralization of the 'name' parameter within a POST request to the login endpoint. A remote, unauthenticated attacker can inject malicious SQL commands to bypass authentication and execute queries with DBA-level privileges. Furthermore, attackers can retrieve the results of these injected queries through subsequent session requests, facilitating the extraction of plaintext credentials and sensitive database content. The vulnerability affects versions up to and including 2.1.2.0.
Affected products
- Linknat (Kunshi Network Technology) VOS3000 through 2.1.2.0
- Linknat (Kunshi Network Technology) VOS2009 through 2.1.2.0
Timeline
- 2015-10-09: disclosed: Initial discovery reported on WooYun (WooYun-2015-145458)
- 2015-10-13: other: Vulnerability confirmed by CNVD
- 2016-01-11: advisory: Public disclosure of vulnerability details
- 2026-07-21: advisory: CVE-2016-20096 published to NVD dataset