Ultra Elegant Ip Phone Sip T41p Firmware
ultra-elegant_ip_phone_sip-t41p_firmware
Vendor: Yealink • 3 CVEs
CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Yealink 1Ultra Elegant Ip Phone Sip T41p Firmware Nov 21, 2024 May 29, 2019 N/A· v4 8.0 HIGH· v3 7.7 HIGH· v2 The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get a...Show more |
1Yealink 1Ultra Elegant Ip Phone Sip T41p Firmware Nov 21, 2024 May 29, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote attacker to trigger code execution or settings modification on the devi...Show more |
1Yealink 1Ultra Elegant Ip Phone Sip T41p Firmware Nov 21, 2024 May 29, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker to trigger OS commands or open a reverse shell via command injection. |