Junglewise Threat Intelligence

CVE-2025-57457: Curo UC300 OS command injection in Admin panel

CVE-2025-57457 · Severity: high · CVSS 8.8 · Published 2025-10-08

Executive brief

A security vulnerability exists in the Curo UC300 IP phone's administration interface. An attacker with access to the device's management panel can execute unauthorized system commands by entering malicious data into the network diagnostics tool. This could allow an attacker to take full control of the device, intercept communications, or disrupt phone services.

Technical details

An OS command injection vulnerability (CWE-78) exists in the web-based administration panel of Curo UC300 IP phones running firmware version 5.42.1.7.1.63R1. The flaw is located within the Network Diagnostics component, specifically in the 'IP Addr' input field. An attacker with low-privileged access to the admin panel can bypass input validation to append arbitrary Linux commands to the intended diagnostic utility. Successful exploitation grants the attacker the ability to execute code with the privileges of the web server, potentially leading to full device compromise. The vendor has reportedly released updated firmware to address this issue.

Affected products

  • Curo UC300 IP Phone 5.42.1.7.1.63R1

Timeline

  • 2025-07-03: disclosed: Issue reported to vendor
  • 2025-09-19: patched: Vendor confirmed issue and rolled out updated firmware to production
  • 2025-10-08: advisory: CVE published

References