Critical severity9.9NVD Advisory· Published Jun 10, 2025· Updated Jun 17, 2026
CVE-2025-1041
CVE-2025-1041
Description
An improper input validation discovered in
Avaya Call Management System could allow an unauthorized
remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:*range: >=18.0.0.1,<19.2.0.7
- (no CPE)range: 18.x, 19.x < 19.2.0.7, 20.x < 20.0.1.0
- Range: 18.0
Patches
Vulnerability mechanics
References
1- support.avaya.com/css/public/documents/101093084nvdVendor Advisory
News mentions
0No linked articles in our index yet.