#VoIP
All CosmicBytez Labs articles tagged #VoIP, across news, security advisories, how-to guides, and projects.
- Security
CVE-2025-70518, CVE-2025-70521, CVE-2025-70516: Fanvil X7A Firmware Unauthenticated Command Injection and Access Control Bypass
Three critical Fanvil X7A VoIP phone firmware flaws allow unauthenticated remote code execution and device data exposure.
- News
Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells
A critical unauthenticated SQL injection in Sangoma Switchvox is under active exploitation, dropping reverse shells on roughly 4,000 exposed PBXs.
- Security
CVE-2026-45538: OpenSIPS Stack Buffer Overflow via Oversized SIP Header
A critical stack buffer overflow in OpenSIPS versions 4.0.0 and prior allows remote code execution by sending a SIP message with a header name exceeding...
- News
Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
A stack-based buffer overflow flaw in HP OfficeConnect VoIP phones can be exploited remotely to achieve code execution, potentially allowing attackers to…
- Security
Critical Grandstream VoIP Vulnerability Allows
A critical CVSS 9.3 stack-based buffer overflow in Grandstream GXP1600 series VoIP phones allows unauthenticated remote code execution, enabling attackers...