High severity8.8NVD Advisory· Published Jul 29, 2020· Updated Jun 17, 2026
CVE-2019-20029
CVE-2019-20029
Description
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.
Affected products
9- cpe:2.3:o:nec:sl1100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:nec:sl2100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:nec:sv8100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:nec:sv9100_firmware:*:*:*:*:*:*:*:*
- NEC/NEC PBXesdescription
Patches
Vulnerability mechanics
References
1- shadytel.su/files/nec_cve.txtnvdThird Party Advisory
News mentions
0No linked articles in our index yet.