CVE-2026-0786
7.5ALGO · 8180 IP Audio Alerter
The ALGO 8180 IP Audio Alerter contains an OS command injection vulnerability in the SCI module, allowing authenticated remote attackers to execute arbitrary code.
Executive summary
A critical command injection vulnerability in the ALGO 8180 IP Audio Alerter allows authenticated attackers to achieve remote code execution on the device.
Vulnerability
The vulnerability resides in the SCI module of the device and stems from improper validation of user-supplied strings before they are processed by a system call. Exploitation requires the attacker to possess valid credentials to access the device.
Business impact
A successful exploit grants an attacker the ability to execute arbitrary commands with the privileges of the device service. This poses a significant risk to operational security, potentially allowing an attacker to gain persistent control over the audio alerting infrastructure, intercept communications, or pivot into the internal network. Given the CVSS score of 7.5, this is considered a High severity issue that requires immediate attention to protect sensitive facility communications.
Remediation
Immediate Action: Restrict network access to the management interface of the affected devices to trusted subnets only until a manufacturer patch is available.
Proactive Monitoring: Review device access logs for suspicious administrative activity or unusual command strings directed at the SCI module interface.
Compensating Controls: Implement strict network segmentation and utilize a firewall to block unauthorized access to the device management ports from untrusted network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing the ALGO 8180 IP Audio Alerter should immediately audit their network exposure and ensure that administrative interfaces are not reachable from external or untrusted networks. While a patch is not yet confirmed, maintaining a strong perimeter defense and monitoring for anomalous authentication patterns is essential to mitigating the risk posed by this command injection flaw.