{"advisories":[{"id":"EUVD-2025-18777","source":"euvd","title":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18777"}],"cve":"CVE-2025-34023","enrichment":{"analysis":{"en":{"generated_at":"2026-04-28T11:12:51.200123+00:00","value":{"mitigation_remediation":["Upgrade the device to the latest firmware version provided by Karel that fixes the path traversal vulnerability in the /cgi-bin/cgiServer.exx endpoint.","Restrict external access to the web management interface by enabling firewall rules that permit only trusted internal IP addresses and by ensuring the interface is not exposed to the internet.","Enforce strong authentication mechanisms, such as password complexity requirements and two‑factor authentication, and regularly review access logs for unusual activity on the web console."],"summary":{"action":"Patch Immediately","impact":"Remote File Access leading to potential confidentiality compromise"},"threat_synthesis":{"affected_systems":"The vulnerability affects Karel IP Phones of the IP1211 model. No version range is specified beyond the model, meaning all units running the default firmware expose this issue.","description_and_impact":"A path traversal flaw exists in the web management interface of the Karel IP1211 IP Phone, specifically within the /cgi-bin/cgiServer.exx endpoint. The server fails to sanitize the \"page\" query parameter, allowing an attacker to craft URLs that traverse directories and read arbitrary files from the device’s underlying file system. This can expose configuration files, credentials, or even binary code, and could be leveraged further to execute code or pivot within a network. The weakness is identified as CWE-22, a file or directory traversal vulnerability.","risk_and_exploitability":"The CVSS score of 8.5 indicates high severity, and the EPSS score of 3% suggests that the likelihood of exploitation is non‑negligible but not pervasive. The vendor has not listed this issue in the CISA KEV catalog. Attackers need to be authenticated to the web management interface to exploit the flaw, implying that compromised credentials or insider access would be a prerequisite. Once authenticated, the attacker can retrieve any file readable by the web process, potentially enabling further attacks."}}}},"created":"2026-04-28T11:15:26.098133+00:00","updated":"2026-04-28T11:15:26.098145+00:00","vendors":[]},"epss":{"score":0.01572},"mitre":{"cpes":[],"created":"2025-06-20T18:37:45.496000+00:00","description":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":8.5,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"}},"mitre_repo_path":"cves/2025/34xxx/CVE-2025-34023.json","references":["https://cxsecurity.com/issue/WLB-2020100038","https://vulncheck.com/advisories/selea-targa-ip-camera-path-traversal","https://web.archive.org/web/20201020023943/https://www.karel.com.tr/urun-cozum/ip1211-ip-telefon","https://www.exploit-db.com/exploits/48857"],"title":"Karel IP Phone IP1211 Path Traversal","updated":"2026-04-07T14:09:02.670000+00:00","vendors":[],"weaknesses":["CWE-22"]},"nvd":{"cpes":[],"created":"2025-06-20T19:15:36.887000+00:00","description":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":8.5,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2025/CVE-2025-34023.json","references":["https://cxsecurity.com/issue/WLB-2020100038","https://vulncheck.com/advisories/selea-targa-ip-camera-path-traversal","https://web.archive.org/web/20201020023943/https://www.karel.com.tr/urun-cozum/ip1211-ip-telefon","https://www.exploit-db.com/exploits/48857"],"title":null,"updated":"2026-06-17T09:13:19.497000+00:00","vendors":[],"weaknesses":["CWE-22"]},"opencve":{"changes":[{"created":"2025-06-20T19:00:00+00:00","data":[{"details":{"new":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow.","old":null},"type":"description"},{"details":{"new":"Karel IP Phone IP1211 Path Traversal","old":null},"type":"title"},{"details":{"added":["CWE-22"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://cxsecurity.com/issue/WLB-2020100038","https://vulncheck.com/advisories/selea-targa-ip-camera-path-traversal","https://web.archive.org/web/20201020023943/https://www.karel.com.tr/urun-cozum/ip1211-ip-telefon","https://www.exploit-db.com/exploits/48857"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":8.5,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"6d2ad600-b4f1-44ac-92e6-2b1893c107f9"},{"created":"2025-06-23T21:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"4978f54e-5384-45ac-90cc-7fc3e63f94dc"},{"created":"2025-11-20T16:15:00+00:00","data":[{"details":{"new":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-10-06 UTC.","old":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow."},"type":"description"}],"id":"856a1730-4bba-4c20-b295-d74d6728ae79"},{"created":"2025-11-20T21:30:00+00:00","data":[{"details":{"new":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.","old":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-10-06 UTC."},"type":"description"}],"id":"6a984395-5ad7-4e22-aaef-48a4903eaf40"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2025-06-20T18:37:45.496000+00:00","provider":"mitre"},"description":{"data":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":8.5,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"},"provider":"mitre"},"epss":{"data":{"score":0.01572},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://cxsecurity.com/issue/WLB-2020100038","https://vulncheck.com/advisories/selea-targa-ip-camera-path-traversal","https://web.archive.org/web/20201020023943/https://www.karel.com.tr/urun-cozum/ip1211-ip-telefon","https://www.exploit-db.com/exploits/48857"],"providers":["mitre","nvd"]},"title":{"data":"Karel IP Phone IP1211 Path Traversal","provider":"mitre"},"updated":{"data":"2026-04-15T00:35:42.020000+00:00","provider":"nvd"},"vendors":{"data":[],"providers":[]},"weaknesses":{"data":["CWE-22"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-06-20T18:37:45.496000+00:00","description":"A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Karel IP Phone IP1211 Path Traversal","updated":"2025-06-23T20:38:12.238000+00:00","vendors":[],"vulnrichment_repo_path":"2025/34xxx/CVE-2025-34023.json","weaknesses":[]}}