PT-2014-2953 · Yealink · Yealink Voip Phone Sip-T38G
Mr.Un1K0D3R
·
Publicado
2014-08-03
·
Atualizado
2014-08-04
·
CVE-2013-5758
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Yealink VoIP Phone SIP-T38G
Description
The issue allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request. This can be used to run unauthorized services, change directory permissions, and modify files.
Recommendations
For Yealink VoIP Phone SIP-T38G, consider restricting access to the cgi-bin/cgiServer.exx to prevent unauthorized command execution until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation.
Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Yealink Voip Phone Sip-T38G