Metrics
Affected Vendors & Products
Mon, 15 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection | |
| First Time appeared |
Yealink
Yealink sip-t46u |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:yealink:sip-t46u:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yealink
Yealink sip-t46u |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-06-15T04:30:12.020Z
Updated: 2026-06-15T21:55:59.368Z
Reserved: 2026-06-14T13:54:13.580Z
Link: CVE-2026-12219
Updated: 2026-06-15T21:55:54.462Z
Status : Deferred
Published: 2026-06-15T06:16:23.953
Modified: 2026-06-15T20:42:32.707
Link: CVE-2026-12219
No data.
ReportizFlow