CVE-2025-1041 CRITICAL

CVE-2025-1041: Avaya Call Management System RCE vulnerability

Vendor Avaya
Product Avaya Call Management System
Weakness CWE-20 · Input validation
Published June 10, 2025
Last update June 10, 2025

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.

Key dates

02Disclosure timeline

June 10, 2025 CVE published
June 10, 2025 Record updated