Showing 1 vulnerability on this page for sip-t38g

Signals CISA KEV Ransomware Nuclei
Yealink vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Yealink sip-t38g Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.

CWE-78Aug 3, 2014
CVSS9.0v2.0EPSS11.9%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX