
PoC بلغة Python لثغرة CVE-2026-21010 يعيد تشغيل ترويسات SIP digest Authorization الملتقطة لتجاوز فرادة/انتهاء صلاحية nonce وإجراء مكالمات VoIP غير مصرح بها.
# sip_server_sim.py - SIP server that accepts replayed authenticated requests
from flask import Flask, request
app = Flask(__name__)
# Simulated nonce storage: doesn't track used nonces
used_nonces = set()
@app.route('/call', methods=['POST'])
def call():
auth_header = request.headers.get('Authorization')
if not auth_header:
return 'Unauthorized', 401, {'WWW-Authenticate': 'Digest realm="test", nonce="abc123"'}
# Vulnerability: no replay protection; accepts the same nonce repeatedly
# In real SIP, a nonce should be used once; here we skip that check.
return "Call connected"
if __name__ == '__main__':
app.run(port=5060)
يطبّق خادم SIP مصادقة Digest لكنه لا يفرض تفرد nonce أو انتهاء صلاحيتها. يمكن للمهاجم التقاط ترويسة Authorization صالحة واحدة وإعادة إرسالها لإجراء مكالمات غير مصرح بها، متجاوزًا بذلك المصادقة.
pip install flask
python sip_server_sim.py
python exploit_sip_replay.py
ينجح الطلب المُعاد إرساله.