Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
References
| Link | Resource |
|---|---|
| http://tiptel.com | Product |
| https://www.bdosecurity.de/en-gb/advisories/cve-2024-33109 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-09-19 19:15
Updated : 2024-09-25 14:47
NVD link : CVE-2024-33109
Mitre link : CVE-2024-33109
CVE.ORG link : CVE-2024-33109
JSON object : View
Products Affected
yealink
- sip-t28p_firmware
- sip-t28p
ergophone
- tiptel_ip_286
- tiptel_ip_286_firmware
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
