Junglewise Threat Intelligence

CVE-2026-9003: TONNET E-LAN Hybrid Recording System SQL injection

CVE-2026-9003 · Severity: high · CVSS 7.5 · Published 2026-05-20

Executive brief

The TONNET E-LAN Hybrid Recording System, a device used for recording and managing telephone communications, contains a security flaw. An unauthenticated attacker can remotely access the system's database to read sensitive information. This could lead to the exposure of call logs, system configurations, or other private data stored on the recording appliance.

Technical details

A SQL injection vulnerability (CWE-89) exists in the TONNET E-LAN Hybrid Recording System (specifically model TPR7308). The flaw is caused by improper neutralization of special elements used in SQL commands, allowing an unauthenticated attacker to send malicious queries over the network. Successful exploitation enables the attacker to execute arbitrary SQL commands to extract sensitive data from the backend database. The vulnerability is addressed in firmware version mdiskTRS08_tonnet_20260203-1636 or later.

Affected products

  • TONNET E-LAN Hybrid Recording System (TPR7308) Versions prior to mdiskTRS08_tonnet_20260203-1636

Timeline

  • 2026-05-19: disclosed: Initial disclosure by TWCERT/CC
  • 2026-05-20: advisory: NVD publication date
  • 2026-02-03: patched: Firmware patch released

References