PT-2014-2953 · Yealink · Yealink Voip Phone Sip-T38G

Mr.Un1K0D3R

·

Publicado

2014-08-03

·

Atualizado

2014-08-04

·

CVE-2013-5758

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yealink VoIP Phone SIP-T38G
Description The issue allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request. This can be used to run unauthorized services, change directory permissions, and modify files.
Recommendations For Yealink VoIP Phone SIP-T38G, consider restricting access to the cgi-bin/cgiServer.exx to prevent unauthorized command execution until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-5758

Produtos afetados

Yealink Voip Phone Sip-T38G