CVE-2007-0528
Status: ModifiedHigh (9)—💥 Exploit
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
- Base score: 9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.49%
- Percentile among all scored CVEs: 91
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · PA168 Chipset IP Phones - Weak Session Management (1/24/2007)
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://osvdb.org/32966
- http://secunia.com/advisories/23919
- http://secunia.com/advisories/23936
- http://www.procheckup.com/Vulner_PR0614.php
- http://www.securityfocus.com/archive/1/457868/100/0/threaded
- http://www.vupen.com/english/advisories/2007/0346
- https://www.exploit-db.com/exploits/3189
- http://osvdb.org/32966
- http://secunia.com/advisories/23919
- http://secunia.com/advisories/23936
- http://www.procheckup.com/Vulner_PR0614.php
- http://www.securityfocus.com/archive/1/457868/100/0/threaded
- http://www.vupen.com/english/advisories/2007/0346
- https://www.exploit-db.com/exploits/3189
Raw JSON (NVD)
Show
{
"id": "CVE-2007-0528",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-01-26T01:28:00.000",
"references": [
{
"url": "http://osvdb.org/32966",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/23919",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/23936",
"source": "cve@mitre.org"
},
{
"url": "http://www.procheckup.com/Vulner_PR0614.php",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/457868/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0346",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/3189",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/32966",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/23919",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/23936",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.procheckup.com/Vulner_PR0614.php",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/457868/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0346",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/3189",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data)."
},
{
"lang": "es",
"value": "La consola del web admin implementada por Centrality Communications (también conocido como Aredfox) PA168 chipset y firmware 1.54 y anteriores, \t\r\nen la manera prevista por varios teléfonos del IP, no requiere contraseñas o validación de tokens cuando se usa HTTP, lo cual permite a atacantes remotos conetar a un superusuario existente sesiones y obtener información sensible (contraseñas y configuración de datos)."
}
],
"lastModified": "2026-06-16T22:35:45.330",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:centrality_communications:pa168_chipset:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0D97ED7-1757-49B2-98E8-6DD8192DC5A0",
"versionEndIncluding": "firmware_1.54"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}