header-logo
Suggest Exploit
vendor:
VoIP Phone SIP-T38G
by:
Mr.Un1k0d3r & Doreth.Z10 From RingZer0 Team
7,5
CVSS
HIGH
Hardcoded Credentials
259
CWE
Product Name: VoIP Phone SIP-T38G
Affected Version From: VoIP Phone SIP-T38G
Affected Version To: VoIP Phone SIP-T38G
Patch Exists: Yes
Related CWE: CVE-2013-5755
CPE: h:yealink:voip_phone_sip-t38g
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013

Yealink VoIP Phone SIP-T38G Default Credentials

The web interface of the Yealink VoIP Phone SIP-T38G uses hardcoded default credentials in the /config/.htpasswd file. The cleartext passwords for these accounts are user:user, admin:admin, and var:var.

Mitigation:

Ensure that all default credentials are changed to unique, strong passwords.
Source

Exploit-DB raw data:

Title: Yealink VoIP Phone SIP-T38G Default Credentials
Author: Mr.Un1k0d3r & Doreth.Z10 From RingZer0 Team
Vendor Homepage: http://www.yealink.com/Companyprofile.aspx
Version: VoIP Phone SIP-T38G
CVE: CVE-2013-5755

Description:

Web interface use hardcoded default credential in /config/.htpasswd


user:s7C9Cx.rLsWFA admin:uoCbM.VEiKQto var:jhl3iZAe./qXM

Here's the cleartext password for these accounts:

user:user
admin:admin
var:var

-- 
*Mr.Un1k0d3r** or 1 #*