medium · CVSS v3 5.3 · CVSS v4 6.9 · EPSS 0.00286
CVE-2026-96774
CVE-2026-96774 is a remote information disclosure vulnerability in the Configuration File Download component of SPON Communications' XC-9603
Overview
CVE-2026-96774 is a remote information disclosure vulnerability in the Configuration File Download component of SPON Communications' XC-9603 IP Network Audio Device. The flaw allows attackers to read sensitive configuration data via the loadCfg function. It could expose device settings and network credentials.
Description
A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of the component Configuration File Download. The manipulation results in information disclosure. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
The vulnerability compromises confidentiality by exposing configuration files that may contain passwords, network topology, and other sensitive data. Attackers can gain insight into the device’s internal settings, potentially facilitating further attacks. Defenders should treat exposed data as compromised and consider it a breach of confidentiality. The impact is limited to information disclosure; no direct integrity or availability impact is reported.
Remediation
Apply the vendor’s patch or firmware update that fixes the loadCfg handling in /ini/sys_cfg.txt. If no patch is available, block remote access to the Configuration File Download service via firewall or ACLs, and disable the loadCfg functionality if possible. Monitor device logs for unauthorized configuration download attempts.
Risk context
With a medium CVSS score of 5.3 and an EPSS of 0.00286, the risk is low but still present. The lack of vendor response increases uncertainty. Defenders should prioritize patching or network segmentation to mitigate potential exposure.
Affected products
- SPON Communications XC-9603 1.2.3_20181106 Build 107
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- 0.00286