Back to CVE List

CVE-2026-12218

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.0 / 10
Vector String
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local network is required for this attack. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-119
Source
NVD
Vendor
Yealink
Product
SIP-T46U

External References

Discussion (0)

Add Comment

No comments yet. Be the first!