CVE-2012-1417: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1417?
CVE-2012-1417 is rated as a medium severity vulnerability due to its potential to allow unauthorized script execution.
How do I fix CVE-2012-1417?
To fix CVE-2012-1417, update the Yealink VOIP phones to the latest firmware provided by the manufacturer.
What types of devices are affected by CVE-2012-1417?
CVE-2012-1417 affects multiple Yealink VOIP phone models including SIP-T32G, SIP-T38G, and SIP-T21P among others.
Can CVE-2012-1417 be exploited remotely?
Yes, CVE-2012-1417 can be exploited remotely by authenticated users to inject arbitrary web scripts.
What are the signs of exploitation of CVE-2012-1417?
Signs of exploitation may include unexpected behavior on the device interface and unauthorized changes to the phone settings.