CVE-2013-5757: Path Traversal
Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parameter to cgi-bin/cgiServer.exx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5757?
CVE-2013-5757 is considered a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2013-5757?
To fix CVE-2013-5757, update the Yealink SIP-T38G firmware to the latest version that addresses this vulnerability.
Who is affected by CVE-2013-5757?
Users of Yealink SIP-T38G VoIP phones are affected by CVE-2013-5757 if they have remote authenticated access enabled.
What type of vulnerability is CVE-2013-5757?
CVE-2013-5757 is classified as an absolute path traversal vulnerability.
What can an attacker do using CVE-2013-5757?
An attacker can exploit CVE-2013-5757 to read arbitrary files on the device by using a full pathname in specific command parameters.