Directory Traversal Vulnerability in Yealink VoIP Phone SIP-T38G
CVE-2013-5756

Currently unrated

Key Information:

Vendor

Yealink

Status
Vendor
CVE Published:
3 August 2014

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2013-5756?

A directory traversal vulnerability exists in Yealink VoIP Phone SIP-T38G, allowing remote authenticated users to exploit the system by manipulating parameters within URLs. This flaw enables attackers to access arbitrary files on the server, potentially exposing sensitive information. The vulnerability arises from improper handling of user-supplied input in the page parameter, permitting traversal up the directory structure.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.