The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated malicious user to trigger OS commands or open a reverse shell via command injection.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
yealink ultra-elegant_ip_phone_sip-t41p_firmware 66.83.0.35 |