Security Advisory
CVE-2018-18871
9.8
CRITICAL
Vulnerability Description
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).
Published Date
December 20, 2018
Official Source
NIST NVD Advisory