33739exploit
http://www.exploit-db.com/exploits/33739 CVE-2013-5755
Yealink VoIP Phone SIP-T38G - Default Credentials
Record summary
CVE-2013-5755 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) for the var account, which makes it easier for remote attackers to obtain access via unspecified vectors.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBYealink VoIP Phone SIP-T38G - Default CredentialsExploitDB exploitby Mr.Un1k0d3rNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-5755