📦 E11 Firmware

by Akuvox

🔍 What is E11 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-0344

CRITICAL CVSS 9.1 Mar 31, 2023

Akuvox E11 devices use a custom Dropbear SSH server with an insecure option not present in official versions, potentially allowing unauthorized access. This affects Akuvox E11 devices running vulnerab...

CVE-2023-0345

CRITICAL CVSS 9.8 Mar 13, 2023

The Akuvox E11 device has SSH enabled by default with a hardcoded root password that cannot be changed. This allows attackers to gain full administrative control over affected devices. Organizations u...

CVE-2023-0352

CRITICAL CVSS 9.1 Mar 13, 2023

The Akuvox E11 password recovery webpage is accessible without authentication, allowing attackers to download the device key file and reset the password to default. This affects users of Akuvox E11 de...

CVE-2023-0354

CRITICAL CVSS 9.1 Mar 13, 2023

The Akuvox E11 web server lacks authentication controls, allowing unauthenticated attackers to access sensitive information and create/download packet captures via default URLs. This affects organizat...

CVE-2023-0347

HIGH CVSS 7.5 Mar 13, 2023

This vulnerability allows attackers to identify Akuvox E11 devices on the Akuvox cloud by combining MAC and IP addresses. This affects organizations using Akuvox E11 devices connected to the Akuvox cl...

CVE-2023-0349

HIGH CVSS 7.5 Mar 13, 2023

The Akuvox E11's libvoice library has an authentication bypass vulnerability that allows unauthenticated access to camera capture functionality. Attackers can remotely view and record images/videos fr...

CVE-2023-0351

HIGH CVSS 8.8 Mar 13, 2023

This vulnerability allows remote command injection in Akuvox E11 devices through the phone-book contacts functionality. Attackers can upload files containing executable commands, potentially gaining f...