← Back

CVE-2013-5758

nvd nist
Published: Aug 3, 2014Modified: May 6, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.

Affected (1)

Products: Yealink: Sip T38g
1 product
Sip T38g
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Timeline

No history available yet.