S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-40856 Scanner

CVE-2021-40856 scanner - Authentication Bypass vulnerability in Auerswald COMfortel 1400 IP and 2600 IP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
5.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-40856
7.5
CVSS

Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Auerswald COMfortel 1400 IP and 2600 IP are VoIP phones designed for business use. They are equipped with a host of features that make them suitable for use in small to medium-sized business environments, such as high-quality audio, flexible configuration options, and a user-friendly interface. These devices are popular among businesses that need to communicate with customers, suppliers, and employees in different locations.

Recently, a vulnerability was detected in these devices, known as CVE-2021-40856. This vulnerability allows attackers to bypass authentication by using the /about/../ substring. This means that an attacker can gain unauthorized access to the device without needing a username or password. This vulnerability can also be exploited remotely, making it a serious threat to the security of businesses that rely on these devices.

If this vulnerability is exploited, it can lead to a number of serious consequences. For example, an attacker could use the device to make unauthorized calls, listen in on conversations, or even plant malware on the network. Additionally, an attacker could use the device as a springboard to launch further attacks against other devices on the network.

At s4e.io, our pro features enable you to quickly and easily identify vulnerabilities in your digital assets. Our platform scans your devices and networks for vulnerabilities, and provides you with detailed reports on any issues found. With our platform, you can rest assured that your business is protected against the latest threats, including the CVE-2021-40856 vulnerability detected in the Auerswald COMfortel 1400 IP and 2600 IP devices.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability. These precautions include:

  • Updating the firmware of the device to the latest version
  • Configuring the device to only allow connections from trusted sources
  • Disabling any unnecessary features or services on the device
  • Monitoring the device for suspicious activity
  • Enforcing strong password policies and two-factor authentication

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-40856 scanner - Authentication Bypass vulnerability in Auerswald COMfortel 1400 IP and 2600 IP | S4E