ZeroHour

CVE-2007-3010

KEVmoderate

Command Injection RCE in Alcatel OmniPCX Enterprise masterCGI

CISA: Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

CVSS
EPSS
97%p100
Published
KEV added
AI analysis

CVE-2007-3010 is a command execution flaw in masterCGI, a component of the Unified Maintenance Tool in the Alcatel OmniPCX Enterprise Communication Server. Because the CGI fails to properly validate user-supplied input (CWE-20), a remote attacker can send crafted requests to the web-based maintenance interface and inject arbitrary operating system commands, which are executed on the PBX server. Successful exploitation yields remote code execution on the communication server, giving attackers a foothold on a Linux-based edge device that could be used for further compromise, lateral movement into the voice network, or, per recent botnet trends, conscription into proxy botnets. Any organization running an Alcatel OmniPCX Enterprise communication server with the Unified Maintenance Tool reachable is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) with a very high 97.4% EPSS score, indicating active in-the-wild exploitation, though no public proof-of-concept code is known.

What to do: Apply updates per vendor instructions (Alcatel/Aastra/Alcatel-Lucent Enterprise maintenance releases) as required by CISA's KEV catalog. Until patched, restrict access to the Unified Maintenance Tool web interface (masterCGI) to trusted management networks only, e.g., via firewall or ACL rules, and avoid exposing it to the internet. Given recent Mirai-based botnets targeting Linux edge devices, audit OmniPCX servers for signs of compromise such as unexpected processes or outbound proxy (SOCKS5) traffic.

Affected
Alcatel OmniPCX Enterprise Communication Server (Unified Maintenance Tool / masterCGI)
Estimated exposure
moderateroughly 1,000–10,000 internet-exposed systems (estimate; enterprise PBX deployments with only a fraction exposing the management interface) — OmniPCX Enterprise is a legacy enterprise PBX installed at tens of thousands of business sites over its long product life, but most deployments keep the Unified Maintenance Tool web interface on internal management networks, so only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.

CISA Known Exploited Vulnerability
Affected
Alcatel OmniPCX Enterprise
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Alcatel
Products
OmniPCX Enterprise
Weakness
CWE-20

In the news

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Fortinet researchers documented Evooo1Bot, a new Mirai-derived Linux botnet active since July 2026 that exploits known edge-device flaws to build SOCKS5 proxy networks.

Fortinet FortiGuard Labs identified Evooo1Bot, a previously undocumented Linux botnet built on the leaked Mirai source code, active in the wild since July 2026 and targeting internet-facing edge devices. It exploits numerous known CVEs in routers and devices from D-Link, Tenda, Telesquare, Zyxel, Hikvision, Atlassian Confluence, WSO2, TP-Link, NETGEAR, and others, delivering a bot binary via a wget.sh loader from 91.92.40.118 that clears bash history. The bot offers encrypted C2 on port 443, SSH brute-force scanning, credential sniffing, DDoS over DNS/TCP/UDP, an HTTP exploit dispatcher, and converts infected hosts into SOCKS5 proxies for anonymizing follow-on operations.

The Hacker News · 29d agoMalware in the wildCVE-2007-3010CVE-2016-6277CVE-2018-14558+15 CVEs

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

FortiGuard Labs disclosed Evooo1Bot, a Mirai-based Linux botnet active since July 2026 that hijacks routers and IoT devices for DDoS, credential theft, and SOCKS5 proxying.

Fortinet's FortiGuard Labs disclosed Evooo1Bot, a previously undocumented Linux botnet active since July 2026 that reuses Mirai's DDoS engine while adding encrypted C2, SSH brute-force scanning, credential sniffing, and SOCKS5 proxy modules. The bot exploits 18 known CVEs across Alcatel, NETGEAR, Tenda, D-Link, Telesquare, and Mitsubishi devices, some dating back to 2007, and communicates exclusively over port 443 to blend with HTTPS traffic. Compromised hosts can be turned into SOCKS5 relays for anonymous traffic forwarding or monetization via proxy services. The malware uses AES-256-CTR, ChaCha20, and XOR obfuscation with a 28-command administration interface.

Security Affairs · 28d agoMalware in the wildCVE-2007-3010CVE-2016-6277CVE-2018-14558+7 CVEs