logo

Avaya's IP Phone Security Research - Part A

ID: ea507bde-3e45-5887-b7fc-4de6a5cca370

STIX ID: report--ea507bde-3e45-5887-b7fc-4de6a5cca370

Feed Name: Claroty Team82

Threat Score
65/100

Date Published: 2023-08-22

Date Updated: 2026-04-17

Author: Tal Zohar

...
...

This report documents a detailed technical analysis of Avaya 9608G VoIP phones: extracting unencrypted firmware, reverse-engineering EEPROM structures, desoldering and reading NAND flash (including OOB and Broadcom BCH ECC handling), mounting JFFS2 partitions via nandsim, and finally patching SSH/PAM configuration in the root filesystem to gain root SSH access (root:root). The write-up is a proof-of-concept showing how a skilled adversary with physical access and flash-programming capability can obtain persistent root access to the device.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.