Executive brief
A critical security flaw exists in the login system of Ciser System telecommunications devices. An unauthorized person can use this vulnerability to bypass security and gain full access to the device's configuration data. This could lead to the theft of sensitive information or the compromise of other connected systems on the network.
Technical details
A SQL Injection (SQLi) vulnerability (CWE-89) exists in the authentication module of Ciser System CSIP firmware versions 3.0 through 5.1. The flaw is located in the login interface, where improper neutralization of user-supplied input allows an unauthenticated, remote attacker to execute arbitrary SQL commands. Exploitation requires low attack complexity and no user interaction, potentially leading to a total compromise of the system's configuration data (Confidentiality and Integrity). The vendor has released firmware version 5.3 to address the issue by implementing parameterized queries and improved input validation.
Affected products
- Ciser System SL CSIP firmware 3.0 to 5.1
Timeline
- 2026-03-02: disclosed
- 2026-03-02: advisory
- 2026-03-02: patched: Fixed in version 5.3