QID 730795

Date Published: 2023-05-08

QID 730795: Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability (cisco-sa-spa-unauth-upgrade-UqhyTWW)

A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.
This vulnerability is due to a missing authentication process within the firmware upgrade function.

Affected Versions:
All versions of Cisco SPA112 2-Port Phone Adapters

QID Detection Logic (Unauthenticated):
This QID sends a crafted request to UDP port to check the version of Cisco SPA 112 Phone Adapter.

An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Cisco has not released firmware updates to address this vulnerability. Cisco SPA112 2-Port Phone Adapters have entered the end-of-life process. Customers are encouraged to migrate to a Cisco ATA 190 Series Analog Telephone Adapter. For more information please refer to Cisco Security Advisory

    CVEs related to QID 730795

    Software Advisories
    Advisory ID Software Component Link

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report