The default configuration of the HTTP server in Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not require authentication for sensitive configuration pages, which allows remote attackers to modify configuration.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ip5000_voip_wifi_phone | Hitachi | 1.5.0 (including) | 1.5.0 (including) |
Ip5000_voip_wifi_phone | Hitachi | 1.5.2 (including) | 1.5.2 (including) |
Ip5000_voip_wifi_phone | Hitachi | 1.5.4 (including) | 1.5.4 (including) |
Ip5000_voip_wifi_phone | Hitachi | 1.5.5 (including) | 1.5.5 (including) |
Ip5000_voip_wifi_phone | Hitachi | 1.5.6 (including) | 1.5.6 (including) |
Ip5000_voip_wifi_phone | Hitachi | 1.5.8 (including) | 1.5.8 (including) |
Ip5000_voip_wifi_phone | Hitachi | 1.5.10 (including) | 1.5.10 (including) |