Back to overview

CVE-2026-12223

MEDIUM Exploitation: PoC
5.5
CVSS 3.1
Description
A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection. The attack needs to be initiated within the local network. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2026-12223
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-14 13:54 UTC
Published
2026-06-15 05:30 UTC
Last updated
2026-06-15 10:29 UTC
Primary CWE
CWE-77
Command Injection
Vendor / Product
Yealink / SIP-T46U
Sources
cve.org  ·  NVD

Severity & Metrics

5.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Yealink SIP-T46U 108.86.0.118
Weakness (CWE)
CWESourceDescription
CWE-74 cna Injection
CWE-77 cna Command Injection
CVSS scores (4)
ScoreSeverityVersionSourceVector
5.5 MEDIUM 3.1 cna CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.5 MEDIUM 3.0 cna CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.2 N/D 2.0 cna AV:A/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
5.1 MEDIUM 4.0 cna CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
References (5)
Back to overview