Command Injection Vulnerability in Yeahlink Ultra-elegant IP Phone SIP-T41P (Firmware 66.83.0.35)

Command Injection Vulnerability in Yeahlink Ultra-elegant IP Phone SIP-T41P (Firmware 66.83.0.35)

CVE-2018-16217 · HIGH Severity

AV:N/AC:L/AU:S/C:C/I:C/A:C

The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker to trigger OS commands or open a reverse shell via command injection.

Learn more about our Network Penetration Testing.