CVE detail
CVE-2007-0528 — CVE-2007-0528
Published 2007-01-26 · Modified 2026-06-16 · Vendor centrality_communications · Product pa168_chipset · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0435
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References