Vulnerabilities > Yealink > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-17 CVE-2023-43959 OS Command Injection vulnerability in Yealink Sip-T19P-E2 Firmware 53.84.0.15
An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
network
low complexity
yealink CWE-78
8.8
2019-05-29 CVE-2018-16221 Path Traversal vulnerability in Yealink Ultra-Elegant IP Phone Sip-T41P Firmware 66.83.0.35
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).
low complexity
yealink CWE-22
7.7