vendor:
IP1211 IP Phone
by:
Berat Gokberk ISLER
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: IP1211 IP Phone
Affected Version From: IP1211
Affected Version To: IP1211
Patch Exists: NO
Related CWE:
CPE: a:karel:ip1211_ip_phone
Platforms Tested:
2020
Karel IP Phone IP1211 Web Management Panel – Directory Traversal
Directory traversal vulnerability on the Karel IP1211 IP Phone Web Panel. Remote authenticated users (Attackers used default credentials in this case) to perform directory traversal, provides access to sensitive data under indexes using the "cgiServer.exx?page=" parameter. In this case sensitive files, "passwd" and "shadow" files.
Mitigation:
The vendor should release a patch to fix the directory traversal vulnerability. In the meantime, users can mitigate the risk by ensuring that the IP Phone is not accessible from untrusted networks.