Information Disclosure Vulnerability in SPON Communications IP Network Audio Device
CVE-2026-96774

6.9MEDIUM

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-96774?

A vulnerability exists in the SPON Communications IP Network Audio Device XC-9603 due to improper access control in the configuration file download function. Specifically, the loadCfg function in the /ini/sys_cfg.txt file can be exploited remotely, resulting in unauthorized information disclosure. Despite attempts to inform the vendor, no response was received regarding this serious issue.

Affected Version(s)

IP Network Audio Device XC-9603 1.2.3_20181106 Build 107

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuki-U (VulDB User)
VulDB CNA Team
.