Answer in brief
CVE-2025-34023 records a High severity (CVSS 8.5) vulnerability in Karel IP Phone IP1211 Path Traversal. The current sources do not mark it as known exploited. The current feed maps Karel/Karel IP Phone IP1211 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Karel/Karel IP Phone IP1211 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Karel/Karel IP Phone IP1211generic | >=0 <=* | Not reported |
Published upstream
Jun 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 30, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 30, 2026
A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
Quoted source text, attributed separately from HOL analysis.