S4E just found an informational nextcloud technology detection scanner
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-30461 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in VoIPmonitor affects v. before 24.61.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-30461
9.8
CVSS

A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

VoIPmonitor is a popular software program that offers a wide range of monitoring and analysis tools for VoIP networks. The main purpose of this program is to capture and record important data related to VoIP calls, such as call duration, caller ID, call quality, and more. It can help businesses and organizations of all sizes identify and fix various VoIP-related issues, such as latency, jitter, packet loss, and other network problems.

Recently, a critical vulnerability has been detected in VoIPmonitor version before 24.61. This vulnerability, coded as CVE-2021-30461, relates to a remote code execution issue in the program's web user interface. When using the recheck option in the program, the SPOOLDIR value, which is user-supplied and may contain PHP code, is injected into the configuration.php file. This injection of malicious code can cause numerous problems, including data breaches, server crashes, and unauthorized access to sensitive information.

Exploitation of this vulnerability could lead to devastating consequences for individuals or companies using the VoIPmonitor program. It could allow attackers to gain unauthorized access to network systems, steal sensitive data, and disrupt vital communications infrastructure. Furthermore, compromised VoIP systems can allow attackers to eavesdrop on conversations, steal personal information, or commit other nefarious activities.

In conclusion, it is critical that businesses and organizations stay up-to-date on the latest vulnerabilities and security threats that may impact their digital assets. With the help of the pro features of the s4e.io platform, individuals and companies can learn even more about digital security and vulnerabilities and take proactive steps towards protecting themselves and their important data. So, take this opportunity to learn more, and secure your digital assets.

 

REFERENCES

 

Solution Advice

There are several steps that organizations using VoIPmonitor can take to protect themselves against CVE-2021-30461 and other vulnerabilities. These include:

  • Updating to the latest version of the program that has patched the vulnerability.
  • Limiting user privileges and locking down the program's web interface.
  • Enforcing strong passwords and multi-factor authentication, where possible.
  • Implementing regular vulnerability scanning and intrusion detection.
  • Investing in the security of network infrastructure and utilizing robust security tools and technologies.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-30461 scanner - Remote Code Execution (RCE) vulnerability in VoIPmonitor S4E