Key Information Vulnerability Type: Directory Traversal Affected Device: Karel IP Phone IP1211 Web Management Panel Release Date: 2020-10-07 CVE ID: N/A CWE ID: CWE-22 Vulnerability Author: Berat Gokberk ISLER Vendor Homepage: https://www.karel.com.tr/urun-cozum/ip1211-ip-telefon Version: IP1211 Vulnerability Details Vulnerable Parameter Type: GET Payload: or Sensitive File Access: The and files can be accessed via the parameter. Request and Response Examples First Request First Response Second Request Second Response