Impact
A path traversal flaw exists in the web management interface of the Karel IP1211 IP Phone, specifically within the /cgi-bin/cgiServer.exx endpoint. The server fails to sanitize the "page" query parameter, allowing an attacker to craft URLs that traverse directories and read arbitrary files from the device’s underlying file system. This can expose configuration files, credentials, or even binary code, and could be leveraged further to execute code or pivot within a network. The weakness is identified as CWE-22, a file or directory traversal vulnerability.
Affected Systems
The vulnerability affects Karel IP Phones of the IP1211 model. No version range is specified beyond the model, meaning all units running the default firmware expose this issue.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the EPSS score of 3% suggests that the likelihood of exploitation is non‑negligible but not pervasive. The vendor has not listed this issue in the CISA KEV catalog. Attackers need to be authenticated to the web management interface to exploit the flaw, implying that compromised credentials or insider access would be a prerequisite. Once authenticated, the attacker can retrieve any file readable by the web process, potentially enabling further attacks.
OpenCVE Enrichment
EUVD