TL;DR

Remote attackers can execute arbitrary commands on ALGO 8180 devices via the Web UI, requiring authentication.

What happened

['ALGO 8180 IP Audio Alerter devices are vulnerable to command injection leading to RCE.', 'Authentication is required for exploitation.']

Why it matters for ops

['Remote code execution can lead to full control of the device.', 'Sensitive data and system integrity may be compromised.']

Mitigation

  • Apply firmware updates provided by ALGO
  • Disable unused web services on the device

Action items

  • Update to the latest firmware version as soon as it is available.
  • Review and restrict access controls for web UI.

Detection IOCs

  • Unexpected outbound network connections from affected devices
  • Unusual authentication attempts

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-004/