Back to overview

CVE-2026-12222

HIGH Exploitation: PoC
8.0
CVSS 3.1
Description
A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer overflow. The attack needs to be done within the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2026-12222
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-14 13:54 UTC
Published
2026-06-15 05:15 UTC
Last updated
2026-06-15 13:11 UTC
Primary CWE
CWE-121
Stack-based Buffer Overflow
Vendor / Product
Yealink / SIP-T46U
Sources
cve.org  ·  NVD

Severity & Metrics

8.0 HIGH CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Yealink SIP-T46U 108.86.0.118
Weakness (CWE)
CWESourceDescription
CWE-119 cna Memory Corruption
CWE-121 cna Stack-based Buffer Overflow
CVSS scores (4)
ScoreSeverityVersionSourceVector
8.6 HIGH 4.0 cna CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
8.0 HIGH 3.1 cna CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
8.0 HIGH 3.0 cna CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
7.7 N/D 2.0 cna AV:A/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR
References (5)
Back to overview