CVE-2013-5755: Yealink SIP-t38g
High severity, CVSS 10.0. EPSS: 4.3% chance of exploitation in the next 30 days.
config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) for the var account, which makes it easier for remote attackers to obtain access via unspecified vectors.
Affected products
- Yealink SIP-t38g: affected versions not specified
Published 2014-07-16. Last modified 2026-06-16.