Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells
Hackers are exploiting a vulnerability in Sangoma Switchvox VoIP platform, leading to remote code execution and reverse shell deployment.
Intelligence analysis by Qwen 2.5 (3B)

Hackers are using a SQL injection vulnerability in Sangoma Switchvox to deploy reverse shells, affecting many exposed systems.
Hackers found a way to trick a phone system into running bad code, and they're using it to spy on and control the system. They're sending fake messages to the system and then getting back information about what's happening inside.
Analysis
{"heading_1":"The Vulnerability","content_1":"Once attackers have valid credentials, only 37% of their actions are blocked, highlighting the need for comprehensive security measures.","content_2":"Signs of compromise include suspicious statements in /var/log/switchvox/db-quirks.log and network connections to the observed attacker IP, particularly on port 39323.","content_3":"The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments, providing insights into the effectiveness of current security measures.","heading_2":"Exploitation and Impact","heading_3":"Prevention and Detection"}
Key points
- Hackers are exploiting a SQL injection vulnerability in Sangoma Switchvox to deploy reverse shells.
- The vulnerability affects many exposed systems, including those in the United States.
- System administrators are recommended to upgrade to Switchvox version 8.4.0.2 or later to mitigate the risk.
By upgrading to the latest version of the phone system, users can protect themselves from this kind of attack.
If attackers get past the upgrade, they can still use the system to spy on and control it, so it's important to keep a close eye on any suspicious activity.



