CVE-2026-96774: Information Disclosure in SPON Communications IP Network Audio Device XC-9603
A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of the component Configuration File Download. The manipulation results in information disclosure. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
The vulnerability CVE-2026-96774 affects the SPON Communications IP Network Audio Device XC-9603 version 1.2.3_20181106 Build 107. It resides in the loadCfg function of the /ini/sys_cfg.txt file, which is part of the Configuration File Download component. An attacker can remotely manipulate this function to cause information disclosure. The vendor was notified but did not respond or provide a fix. The CVSS 4.0 base score is 6.9, indicating a medium severity with network attack vector, low complexity, no privileges or user interaction required, and limited confidentiality impact.
Potential Impact
Successful exploitation of this vulnerability allows an unauthenticated remote attacker to disclose sensitive information from the device's configuration files. This could potentially expose configuration details that may aid further attacks or compromise device security. There is no indication of integrity or availability impact.
Mitigation Recommendations
No vendor response or patch is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is provided, restrict network access to the device to trusted users and networks to reduce exposure.
CVE-2026-96774: Information Disclosure in SPON Communications IP Network Audio Device XC-9603
Description
A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of the component Configuration File Download. The manipulation results in information disclosure. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 6.9medium
Affected software
SPON Communications
IP Network Audio Device XC-9603
cpe:2.3:a:spon_communications:ip_network_audio_device_xc-9603:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-96774 affects the SPON Communications IP Network Audio Device XC-9603 version 1.2.3_20181106 Build 107. It resides in the loadCfg function of the /ini/sys_cfg.txt file, which is part of the Configuration File Download component. An attacker can remotely manipulate this function to cause information disclosure. The vendor was notified but did not respond or provide a fix. The CVSS 4.0 base score is 6.9, indicating a medium severity with network attack vector, low complexity, no privileges or user interaction required, and limited confidentiality impact.
Potential Impact
Successful exploitation of this vulnerability allows an unauthenticated remote attacker to disclose sensitive information from the device's configuration files. This could potentially expose configuration details that may aid further attacks or compromise device security. There is no indication of integrity or availability impact.
Mitigation Recommendations
No vendor response or patch is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is provided, restrict network access to the device to trusted users and networks to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-23T16:15:11.535Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab47a57f7a7c54106aa6807
Added to database: 09/24/2026, 01:18:15 UTC
Last enriched: 09/24/2026, 01:32:38 UTC
Last updated: 09/24/2026, 01:58:25 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.