Vulnerability Description
The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version 01_02_07, has a hard-coded username and password, which allows remote attackers to gain administrative access via telnet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fiwin | Ss28S Wifi Voip Sip Skype Phone | 2007-02-01 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-09/0391.html
- http://secunia.com/advisories/22041
- http://www.osnews.com/story.php/15923/Review-FiWin-SS28S-WiFi-VoIP-SIPSkype-Phon
- http://www.securityfocus.com/bid/20154
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29114
- http://archives.neohapsis.com/archives/fulldisclosure/2006-09/0391.html
- http://secunia.com/advisories/22041
- http://www.osnews.com/story.php/15923/Review-FiWin-SS28S-WiFi-VoIP-SIPSkype-Phon
- http://www.securityfocus.com/bid/20154
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29114
FAQ
What is CVE-2006-5038?
CVE-2006-5038 is a vulnerability with a CVSS score of 7.5 (HIGH). The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version 01_02_07, has a hard-coded username and password, which allows remote attackers to gain administrative access via telnet.
How severe is CVE-2006-5038?
CVE-2006-5038 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5038?
Check the references section above for vendor advisories and patch information. Affected products include: Fiwin Ss28S Wifi Voip Sip Skype Phone.