Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox that can lead to remote code execution.

Switchvox is an enterprise VoIP management platform used to configure and monitor business phone systems. Security researchers at Horizon3 identified CVE-2026-9586 as the most serious of 12 flaws they reported to Sangoma on April 10. Sangoma fixed the vulnerabilities in Switchvox version 8.4.0.2, released on July 14.

The flaw affects the /pa HTTP endpoint. The endpoint processes an XML message containing key-value pairs and directly inserts the PhoneIP value into an unparameterized SQL query. Horizon3 demonstrated that a crafted XML request sent with the curl command could exploit the SQL injection to execute operating-system commands remotely.

On August 30, Horizon3 observed active exploitation across multiple honeypots in rapid succession from the source IP address 176.65.148.184. The attacker attempted to establish a reverse shell, collected information about the top processes on the Switchvox system, and sent the data to a remote server in base64-encoded form.

Horizon3 said Shodan showed approximately 4,000 Switchvox devices exposed to the internet, most of them in the United States. The researchers said they had not seen active exploitation of the remaining 11 flaws.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.