Information Disclosure Vulnerability in SPON Communications IP Network Audio Device
CVE-2026-96774
6.9MEDIUM
What is CVE-2026-96774?
A vulnerability exists in the SPON Communications IP Network Audio Device XC-9603 due to improper access control in the configuration file download function. Specifically, the loadCfg function in the /ini/sys_cfg.txt file can be exploited remotely, resulting in unauthorized information disclosure. Despite attempts to inform the vendor, no response was received regarding this serious issue.
Affected Version(s)
IP Network Audio Device XC-9603 1.2.3_20181106 Build 107
