Karel IP Phone IP1211 Path Traversal
58Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.5epss 1.4%
from disclosure to weapon
Published on NVDJun 20
VulnCheckJun 20
exploitation probability
1.4%top 29% of all CVEs
observed exploitation
yesVulnCheck
A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products
Karel · Karel IP Phone IP1211