Executive brief
Aster Telecom Azcall, a telecommunications management platform, contains a security vulnerability in its store management component. An unauthorized attacker can exploit this flaw to interact directly with the underlying database, potentially leading to the theft of sensitive information or disruption of service. Because a public exploit is available and the vendor has not responded to reports, organizations using this software are at immediate risk.
Technical details
A SQL injection vulnerability exists in Aster Telecom Azcall versions 10 and 11 within the HTTP Handler component. The flaw is located in the file /azcall/adm/gestao_loja/sis.php and is triggered via the 't=consultar' action. Specifically, the application fails to properly sanitize the 'nome', 'perfil', and 'status' parameters. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests to execute arbitrary SQL commands. As of the advisory date, the vendor has not acknowledged the issue or provided a patch, and public exploit code is available.
Affected products
- Aster Telecom Azcall 10, 11
Timeline
- 2026-07-12: advisory: Initial disclosure by VulDB/NVD
- 2026-07-12: disclosed: Public exploit made available