← Back

CVE-2024-33109

nvd nist
Published: Sep 19, 2024Modified: Sep 25, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

Affected (2)

1 product
Tiptel Ip 286 Firmware
1 product
Sip T28p Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.61.13.10
Running on/withPlatform Versions
Ergophone
Tiptel Ip 286
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.61.13.10
Running on/withPlatform Versions
Yealink
Sip T28p
All versions

References (2)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.