Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 20 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inextrix
Inextrix astpp |
|
| CPEs | cpe:2.3:a:inextrix:astpp:4.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Inextrix
Inextrix astpp |
Thu, 12 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Astpp
Astpp astpp |
|
| Vendors & Products |
Astpp
Astpp astpp |
Wed, 11 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory. | |
| Title | ASTPP 4.0.1 VoIP Billing - Database Backup Download | |
| Weaknesses | CWE-538 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T01:28:00.430Z
Reserved: 2026-02-01T13:16:06.490Z
Link: CVE-2020-37104
Updated: 2026-02-12T14:51:32.013Z
Status : Analyzed
Published: 2026-02-11T21:16:08.040
Modified: 2026-02-20T20:20:52.220
Link: CVE-2020-37104
No data.
OpenCVE Enrichment
Updated: 2026-02-12T10:00:52Z