PT-2014-2950 · Yealink · Yealink Voip Phone Sip-T38G

Doreth.Z10

+1

·

Published

2014-07-16

·

Updated

2016-05-26

·

CVE-2013-5755

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yealink IP Phone SIP-T38G
Description The issue concerns hardcoded passwords in the config/.htpasswd file of the Yealink IP Phone SIP-T38G. Specifically, the passwords are: user with password s7C9Cx.rLsWFA, admin with password uoCbM.VEiKQto, and var with password jhl3iZAe./qXM. This makes it easier for remote attackers to gain access via unspecified vectors.
Recommendations For Yealink IP Phone SIP-T38G, change the hardcoded passwords for the user, admin, and var accounts to unique and secure passwords to prevent unauthorized access.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5755

Affected Products

Yealink Voip Phone Sip-T38G