Security Advisory CGP-7848-SA - Authenticated Configuration Manipulation Leads to Root Access on Gigaset Nx70 IP PRO Devices
Table of Content
- Table of Content
- Summary
- Affected Products
- Mitigations / Workarounds
- Vulnerability Details
- Acknowledgements
- Timeline
- Contact Information
| Advisory ID: | CGP-7848-SA |
|---|---|
| Publication Date: | 31.07.2026 |
| Last Updated: | 31.07.2026 |
| Advisory Status: | Final |
| Current Version: | V1.0 |
| CVSS v3.0 Base Score: | 7.2 (High) |
Summary
An attacker with access to an internal management interface can manipute the device and this may lead to the disclosure of authentication information and the acquisition of root privileges. This issue is fixed by implemented security hardening measures by restricting execution of potentially risky network-enabled tools and disabling communication forwarding for the mangement interface user.
Affected Products
- Product Name(s): Gigaset N530 IP PRO, N610 IP PRO, N670 IP PRO, N770 IP PRO, N870 IP PRO, N870E IP PRO, IP Base Comfort II, BasicLine IP
- Affected Version(s) / Build(s): v2.68.0 and lower
Mitigations / Workarounds
- Update the device to v2.70.0 or later
- Until the update has been carried out, please follow the Recommendations
Recommendation
The CLI / Secure Shell interface is reserved for technical specialists. It is deactivated by default and can be enabled by the Admin user of the system via WebUI or Provisioning.
Limit the CLI access to prevent the access via Secure Shell. The CLI / Secure Shell allowed can be disabled via WebUI or provisioning.
If the CLI / Secure Shell is needed, follow the following rules:
- For each access CLI should be enabled for a limited time
- For each access a CLI password different to the password of the system should be set
- For each access a different CLI password should be used
Solution / Patch Information
Available Fixes
- Patched Version(s): v2.70.0
- Download / Update Instructions: FAQ - Firmware update - XWiki
Technical Changes
Implemented security hardening measures by restricting execution of potentially risky network-enabled tools and disabling communication forwarding for the mangement interface user.
Vulnerability Details
Description
The Nx70 IP PRO devices contain a service that accepts connection requests from an internal messaging or management interface. An attacker with access to this interface can manipulate device configuration data and trigger the service to establish a connection to an attacker-controlled system. As a result, sensitive authentication material may be exposed, potentially allowing the attacker to gain privileged access to the device.
Conditions Required for Exploitation
The attacker needs access to the system configuration (Authentication data for the system) or to an activated CLI (Authentication data for the CLI).
Impact Assessment
As a result, sensitive authentication material may be exposed, potentially allowing the attacker to gain privileged access to the device. This has a significant impact on confidentiality, integrity and availability.
Severity & Scoring
- CVSS Score: 7.2 (High)
- Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- AV:N (Network) – Vulnerable via the network.
- AC:L (Low) – No special conditions apply after logging in.
- PR:H (High) – The attacker first needs valid login details.
- UI:N (None) – No other user needs to be involved.
- S:U (Unchanged) – The device is rooted, but there has been no change to the scope.
- C:H/I:H/A:H – Complete loss of confidentiality, integrity and availability.
Acknowledgements
We thank the researcher for responsibly reporting this issue.
Timeline
| Event | Date |
|---|---|
| Vulnerability reported | 10.05.2026 |
| Acknowledgement to reporter | 12.05.2026 |
| Issue verified | 20.05.2026 |
| Fix developed | 25.05.2026 |
| Fix tested | 29.05.2026 |
| Fix validated | 24.07.2026 |
| Advisory published | 31.07.2026 |
Contact Information
For questions, further details, or follow‑up reports:
- Security Team Contact: productsecurity@gigaset.com
- Coordinated Vulnerability Disclosure Policy: Vulnerability Disclosure Policy - XWiki