CVE-2026-0781

7.2

ALGO · 8180 IP Audio Alerter

A command injection vulnerability in the ALGO 8180 IP Audio Alerter web interface allows an authenticated attacker to execute arbitrary system commands, potentially leading to remote code execution.

Executive summary

An OS command injection vulnerability in the ALGO 8180 IP Audio Alerter allows authenticated attackers to achieve remote code execution on the device.

Vulnerability

This is an OS command injection vulnerability (CWE-78) located within the web-based user interface. It occurs due to insufficient validation of user-supplied input before it is processed by a system call, requiring administrative or equivalent authentication to exploit.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the privileges of the web interface, which typically results in full control over the affected audio alerter device. Given the CVSS score of 7.2, this represents a high-severity risk that could lead to unauthorized network access, lateral movement, or the use of the device as a pivot point within the internal network.

Remediation

Immediate Action: Contact the vendor immediately to obtain the appropriate firmware update for version 5.5, as no public patch version is currently specified.

Proactive Monitoring: Review web access logs for suspicious input patterns or unusual system commands directed at the device interface.

Compensating Controls: Restrict access to the device web management interface to trusted administrative IP addresses only, and deploy a Web Application Firewall (WAF) to filter malicious command strings.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in the provided data.

Analyst recommendation

Due to the severity of remote code execution, organizations should treat this vulnerability with high priority. Ensure that all ALGO 8180 IP Audio Alerter devices are isolated from untrusted networks and verify with the vendor regarding the availability of a firmware update to address this command injection flaw.

More ALGO CVEs

Sources