CVE-2013-5758: OS Command Injection
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5758?
CVE-2013-5758 is classified as a critical severity vulnerability due to its ability to allow remote command execution.
How do I fix CVE-2013-5758?
To fix CVE-2013-5758, update the Yealink VoIP Phone SIP-T38G to the latest firmware version that addresses this vulnerability.
What types of attacks can exploit CVE-2013-5758?
CVE-2013-5758 can be exploited to execute arbitrary commands, modify files, and change directory permissions on the device.
Who is affected by CVE-2013-5758?
The vulnerability affects users of the Yealink VoIP Phone SIP-T38G who have not secured their devices against unauthorized access.
What are the consequences of CVE-2013-5758 exploitation?
Exploitation of CVE-2013-5758 could lead to unauthorized control over the device, data breaches, or disruption of services.