CVE-2026-0787
8.1ALGO · 8180 IP Audio Alerter
A command injection vulnerability in the SAC module of ALGO 8180 IP Audio Alerter allows unauthenticated remote attackers to execute arbitrary system code.
Executive summary
The ALGO 8180 IP Audio Alerter is vulnerable to remote code execution due to an OS command injection flaw, presenting a critical risk to device integrity.
Vulnerability
The vulnerability exists within the SAC module, where insufficient validation of user-supplied strings allows for OS command injection. This flaw can be triggered by an unauthenticated attacker via a remote network request.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on a network-connected audio device poses a severe security risk. This could lead to full device compromise, unauthorized access to internal network segments, or the use of the device as a pivot point for further lateral movement. With a CVSS score of 8.1, this high-severity vulnerability requires immediate attention to prevent potential exploitation.
Remediation
Immediate Action: Restrict network access to the affected devices by placing them behind a firewall and disabling external access to the SAC module until an official patch is provided by the vendor.
Proactive Monitoring: Review system and network access logs for unusual command patterns or unauthorized requests directed at the SAC module of the 8180 IP Audio Alerter.
Compensating Controls: Deploy a Web Application Firewall or an Intrusion Prevention System to detect and block malicious payloads attempting to inject system commands into the device interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution without authentication, this vulnerability represents a significant risk to organizational infrastructure. Administrators should prioritize isolating affected ALGO 8180 devices from public-facing networks and monitor vendor communications closely for the release of a security patch. Until a fix is verified, assume the device is exposed to any actor with network visibility.