CVE-2013-5755: Critical severity yealink sip-t38g vulnerability
config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) for the var account, which makes it easier for remote attackers to obtain access via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5755?
CVE-2013-5755 is classified with a medium severity level due to the presence of hardcoded passwords that can be exploited.
How do I fix CVE-2013-5755?
To fix CVE-2013-5755, update the firmware of the Yealink SIP-T38G phone to a version that removes the hardcoded passwords.
What accounts are affected by CVE-2013-5755?
CVE-2013-5755 affects the user, admin, and var accounts on the Yealink SIP-T38G phone.
What type of vulnerability is CVE-2013-5755?
CVE-2013-5755 is a security vulnerability resulting from the use of hardcoded credentials in the configuration files.
Can CVE-2013-5755 allow remote access to the device?
Yes, CVE-2013-5755 can allow remote attackers to gain unauthorized access to the Yealink SIP-T38G device.