Unrated severityNVD Advisory· Published Nov 1, 2008· Updated Apr 23, 2026
CVE-2008-4875
CVE-2008-4875
Description
Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for unauthenticated access to sensitive files such as (1) save.dat and (2) apply.log, which can contain other credentials such as the Skype username and password.
Affected products
2cpe:2.3:h:philips_electronics:voip841_dect_phone:1.0.4.48:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:h:philips_electronics:voip841_dect_phone:1.0.4.48:*:*:*:*:*:*:*
- cpe:2.3:h:philips_electronics:voip841_dect_phone:1.0.4.50:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/28978nvdVendor Advisory
- osvdb.org/42941nvd
- securityreason.com/securityalert/4536nvd
- www.securityfocus.com/archive/1/488127/100/200/threadednvd
- www.securityfocus.com/bid/27790nvd
- www.vupen.com/english/advisories/2008/0583nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/40534nvd
- www.exploit-db.com/exploits/5113nvd
News mentions
0No linked articles in our index yet.