PT-2014-2950 · Yealink · Yealink Voip Phone Sip-T38G
Doreth.Z10
+1
·
Published
2014-07-16
·
Updated
2016-05-26
·
CVE-2013-5755
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Yealink IP Phone SIP-T38G
Description
The issue concerns hardcoded passwords in the config/.htpasswd file of the Yealink IP Phone SIP-T38G. Specifically, the passwords are:
user with password s7C9Cx.rLsWFA, admin with password uoCbM.VEiKQto, and var with password jhl3iZAe./qXM. This makes it easier for remote attackers to gain access via unspecified vectors.Recommendations
For Yealink IP Phone SIP-T38G, change the hardcoded passwords for the
user, admin, and var accounts to unique and secure passwords to prevent unauthorized access.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yealink Voip Phone Sip-T38G