An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML.
References
| Link | Resource |
|---|---|
| https://i.imgur.com/aDuiY8q.png | Exploit |
| https://yechiel.xyz/vulnerability-in-vtechs-vcs754a-business-phones-exposes-sip-credentials | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2023-04-27 21:15
Updated : 2023-05-05 18:10
NVD link : CVE-2023-25437
Mitre link : CVE-2023-25437
CVE.ORG link : CVE-2023-25437
JSON object : View
Products Affected
vtech
- vcs754a
- vcs754a_firmware
CWE
CWE-319
Cleartext Transmission of Sensitive Information
