MEDIUM
Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parameter to cgi-bin/cgiServer.exx
Published Aug 3, 2014
4.0
MEDIUMCVSS 2.0
EPSS 2.75%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.