CVE-2024-33109
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
Affected (2)
Products: Ergophone: Tiptel Ip 286 Firmware · Yealink: Sip T28p Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.61.13.10 |
| Running on/with | Platform Versions |
|---|---|
Ergophone Tiptel Ip 286 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.61.13.10 |
| Running on/with | Platform Versions |
|---|---|
Yealink Sip T28p | All versions |
References (2)
Timeline
No history available yet.