CVE-2018-16218: CSRF
Published May 29, 2019
·Updated
A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote attacker to trigger code execution or settings modification on the device by providing a crafted link to the victim.
Affected Software
2 affected components
Yealink Ultra-elegant Ip Phone Sip-t41p Firmware=66.83.0.35
Yealink Ultra-elegant Ip Phone Sip-t41p
Event History
May 29, 2019
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this CSRF vulnerability?
The vulnerability ID for this CSRF vulnerability is CVE-2018-16218.
2
What is the severity of CVE-2018-16218?
The severity of CVE-2018-16218 is high.
3
What is the affected software for CVE-2018-16218?
The affected software for CVE-2018-16218 is the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35.
4
How does CVE-2018-16218 affect the device?
CVE-2018-16218 allows a remote attacker to trigger code execution or settings modification on the Yeahlink Ultra-elegant IP Phone SIP-T41P device.
5
Is there any additional information available about CVE-2018-16218?
Yes, you can find additional information about CVE-2018-16218 in the advisory document provided by Fraunhofer SIT.