Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-1041


An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.


Published

2025-06-10T06:15:22.000

Last Modified

2025-07-30T17:59:01.643

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application avaya call_management_system < 19.2.0.7 Yes
Application avaya call_management_system < 20.0.1.0 Yes

References