RULE(RULE ID:306527)

Rule General Information
Release Date: 2015-07-02
Rule Name: Yealink Voip Phone SIP-T38G 'cgiserver.exx' Remote Command Execution Vulnerability (CVE-2013-5758)
Severity:
CVE ID:
Rule Protection Details
Description: cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: ExploitDB:33741
ExploitDB:33742
Solutions
The vendor has updated advisory on its official website. Please check it for more information.