Junglewise Threat Intelligence

CVE-2025-6918: Ncvav Virtual PBX Software SQL injection

CVE-2025-6918 · Severity: critical · CVSS 9.8 · Published 2025-07-28

Executive brief

A critical security vulnerability has been identified in Ncvav Virtual PBX Software, a system used for managing business telephone communications. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive call logs, user credentials, or the disruption of phone services. This issue allows for complete control over the application's data without requiring any prior login or user interaction.

Technical details

Ncvav Virtual PBX Software contains an SQL injection vulnerability (CWE-89) due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to send specially crafted requests to the application. Successful exploitation enables the attacker to view, modify, or delete sensitive data within the database, and potentially gain full administrative access to the PBX system. The vulnerability is addressed in versions released on or after July 9, 2025.

Affected products

  • Ncvav Virtual PBX Software before 09.07.2025

Timeline

  • 2025-07-28: advisory: Initial disclosure by TR-CERT (USOM)
  • 2025-07-09: patched: Fix released in version 09.07.2025

References