Loading
config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) for the var account, which makes it easier for remote attackers to obtain access via unspecified vectors.
Use CWE-255, Yealink vendor hub and Sip-T38g product page to widen CVE-2013-5755 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-5758, CVE-2013-5757 and CVE-2013-5756 for nearby disclosures in the same product family.