Loading
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.
Use CWE-78, Yealink vendor hub and Sip-T38g product page to widen CVE-2013-5758 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2013-5755, CVE-2013-5757 and CVE-2013-5756 for nearby disclosures in the same product family.