CVE-2012-1417: XSS

Published Sep 17, 2014
·
Updated

Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

Affected Software

14 affected components
Yealink Gigabit Color Ip Phone Sip-t32g
Yealink Gigabit Color Ip Phone Sip-t38g
Yealink Ip Phone Sip-t19p
Yealink Ip Phone Sip-t20p
Yealink Ip Phone Sip-t21p
Yealink Ip Phone Sip-t22p
Yealink Ip Phone Sip-t26p
Yealink Ip Phone Sip-t28p
Yealink Ip Video Phone Vp530
Yealink Ultra-elegant Ip Phone Sip-t41p
Yealink Ultra-elegant Ip Phone Sip-t42g
Yealink Ultra-elegant Ip Phone Sip-t46g
Yealink Ultra-elegant Ip Phone Sip-t48g
Yealink W52p

Event History

Sep 17, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2012-1417?

CVE-2012-1417 is rated as a medium severity vulnerability due to its potential to allow unauthorized script execution.

2

How do I fix CVE-2012-1417?

To fix CVE-2012-1417, update the Yealink VOIP phones to the latest firmware provided by the manufacturer.

3

What types of devices are affected by CVE-2012-1417?

CVE-2012-1417 affects multiple Yealink VOIP phone models including SIP-T32G, SIP-T38G, and SIP-T21P among others.

4

Can CVE-2012-1417 be exploited remotely?

Yes, CVE-2012-1417 can be exploited remotely by authenticated users to inject arbitrary web scripts.

5

What are the signs of exploitation of CVE-2012-1417?

Signs of exploitation may include unexpected behavior on the device interface and unauthorized changes to the phone settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203