A critical, unauthenticated SQL injection flaw in Linknat VOS3000 and VOS2009 softswitch platforms lets remote attackers extract plaintext credentials and other database content with DBA-level privileges.
What Is It
CVE-2016-20096 is an unauthenticated SQL injection vulnerability (CWE-89) in Linknat VOS3000 and VOS2009 through version 2.1.2.0, developed by Kunshi Network Technology Co., Ltd. Remote attackers can execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Malicious SQL injected through the login form can then be retrieved via a subsequent session request, enabling extraction of database content, including plaintext credentials, with DBA-level privileges. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) and a CVSS 4.0 score of 9.3 (CRITICAL).
Why It Matters
The flaw requires no authentication, no privileges, and no user interaction, and is exploitable over the network with low attack complexity (CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Because injection runs at DBA-level privileges, a successful attack yields full confidentiality, integrity, and availability impact against the underlying database, exposing plaintext credentials and other sensitive data on these VoIP softswitch systems.
What's Vulnerable
The following products from Kunshi Network Technology Co., Ltd. are affected:
- Linknat VOS3000; versions 2.1.1.5, 2.1.1.8, and 2.1.2.0
- Linknat VOS2009; versions 2.1.1.5, 2.1.1.8, and 2.1.2.0
The vulnerability is reported to affect these platforms through version 2.1.2.0.
Patch Status
The supplied source material does not include a CISA KEV entry for this CVE, so active exploitation is not confirmed by KEV, and no specific patch, fixed version, or required remediation action is stated in the provided source data. This CVE has not yet been fully analyzed and enriched, its entry remains in a preliminary "Received" state, so downstream details may change. Refer to the vendor for update guidance.
Sources
- Packet Storm; https://packetstorm.news/files/id/137159
- WooYun (archived), https://web.archive.org/web/20160601102456/http://www.wooyun.org/bugs/wooyun-2010-0145458
- Linknat (vendor), https://www.linknat.com/
- VulnCheck Advisory; https://www.vulncheck.com/advisories/linknat-vos3000-vos2009-sql-injection-via-login-jsp