CVE-2013-5758 Information

Description

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request as demonstrated by running unauthorized services changing directory permissions and modifying files.

Reference

http://packetstormsecurity.com/files/127093/Yealink-VoIP-Phone-SIP-T38G-Privilege-Escalation.html http://packetstormsecurity.com/files/127096/Yealink-VoIP-Phone-SIP-T38G-Remote-Command-Execution.html http://www.exploit-db.com/exploits/33741 http://www.exploit-db.com/exploits/33742 http://www.osvdb.org/108080

Share on: