Description
A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version
Credits
Berat Gokberk Isler
References
web.archive.org/...karel.com.tr/urun-cozum/ip1211-ip-telefon
cxsecurity.com/issue/WLB-2020100038
www.exploit-db.com/exploits/48857
vulncheck.com/...sories/selea-targa-ip-camera-path-traversal