CVE-2007-3010Active Exploitation(al-enterprise / omnipcx_enterprise_communication_server)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for al-enterprise omnipcx_enterprise_communication_server systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-06. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • omnipcx_enterprise_communication_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-30); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
omnipcx_enterprise_communication_server

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-30: 2Mentions · 2026-08-16: 1Mentions · 2026-08-18: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-08-16: 1Technical Details · 2026-04-30: 104-3008-1608-18
Signal classification3 categories
Active Exploitation
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-04-302
Active Exploitation1Disclosure1
2026-08-161
Active Exploitation1
2026-08-181
General1
Full discourse4 posts
  • YogSotho@YogSoth0
    General

    Jesus Christ, dev need to update his CVE set: CVE-2007-3010 WTF Bro?! I could definetively help on this. I have a mirainew project waiting to be further develop with many CVE-2026 router and iot exploits... Duuuuude... 2007 WUUUUT?!

    Post summary

    A brief, informal note listing a few CVE identifiers without any actionable or technical information.

    00051273
    2.0K followersView on X
  • Daniel Ortega@dan_in_robots
    Active Exploitation

    @PVynckier CVE-2007-3010 on an active exploit list in 2026. The problem isn't sophisticated malware. It's that someone is still running an unpatched Alcatel OmniPCX on the open internet.

    Post summary

    CVE‑2007‑3010 is still being actively exploited in 2026, as evidenced by its inclusion on an active exploit list, but no new PoC, exploit code, patch, or technical details are provided.

    0001038
    100 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2007-3010: masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.

    Post summary

    The text discloses that CVE-2007-3010 enables remote code execution on Alcatel OmniPCX Enterprise servers, without mentioning PoC, exploitation, or remediation.

    1000032
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2007-3010-omnipcx-enterprise #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text references a reported active exploitation of CVE‑2007‑3010 on Omnipcx Enterprise, but provides no further technical or mitigation details.

    0000023
    128 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appal-enterpriseomnipcx_enterprise_communication_server---

Explore more