vendor:
SIP-TXXXP
by:
tahaafarooq
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: SIP-TXXXP
Affected Version From: 53.84.0.15
Affected Version To: 53.84.0.15
Patch Exists: NO
Related CWE:
CPE: a:yealink:sip-txxxp:53.84.0.15
Platforms Tested: YeaLink IP Phone SIP-T19P (Hardware VOIP Phone)
2021
YeaLink SIP-TXXXP 53.84.0.15 – ‘cmd’ Command Injection (Authenticated)
Using Diagnostic tool from the Networking Tab to perform a Ping or Traceroute, to perform OS command injection
Mitigation:
Apply the latest firmware update provided by the vendor.