PT-2014-2953 · Yealink · Yealink Voip Phone Sip-T38G

Mr.Un1K0D3R

·

Published

2014-08-03

·

Updated

2014-08-04

·

CVE-2013-5758

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yealink VoIP Phone SIP-T38G
Description The issue allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request. This can be used to run unauthorized services, change directory permissions, and modify files.
Recommendations For Yealink VoIP Phone SIP-T38G, consider restricting access to the cgi-bin/cgiServer.exx to prevent unauthorized command execution until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5758

Affected Products

Yealink Voip Phone Sip-T38G