Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
yealink ultra-elegant ip phone sip-t41p - vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2018-16218
A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote malicious user to trigger code execution or settings modification on the device by providing a crafted link to the victim.
Yealink Ultra-elegant Ip Phone Sip-t41p Firmware 66.83.0.35
8.8
CVSSv3
CVE-2018-16217
The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated malicious user to trigger OS commands or open a reverse shell via command injection.
Yealink Ultra-elegant Ip Phone Sip-t41p Firmware 66.83.0.35
8
CVSSv3
CVE-2018-16221
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote malicious user to get access to privileged information (e.g., /etc/passwd) vi...
Yealink Ultra-elegant Ip Phone Sip-t41p Firmware 66.83.0.35
NA
CVE-2012-1417
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
Yealink Gigabit Color Ip Phone Sip-t32g -
Yealink Ip Phone Sip-t28p -
Yealink W52p -
Yealink Ultra-elegant Ip Phone Sip-t41p -
Yealink Gigabit Color Ip Phone Sip-t38g -
Yealink Ip Phone Sip-t19p -
Yealink Ip Video Phone Vp530 -
Yealink Ultra-elegant Ip Phone Sip-t46g -
Yealink Ultra-elegant Ip Phone Sip-t42g -
Yealink Ip Phone Sip-t21p -
Yealink Ip Phone Sip-t20p -
Yealink Ultra-elegant Ip Phone Sip-t48g -
Yealink Ip Phone Sip-t26p -
Yealink Ip Phone Sip-t22p -
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started