CVE-2018-16221: Path Traversal
Published May 29, 2019
·Updated
The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).
Affected Software
2 affected components
Yealink Ultra-elegant Ip Phone Sip-t41p Firmware=66.83.0.35
Yealink Ultra-elegant Ip Phone Sip-t41p
Event History
May 29, 2019
CVE Published
via MITRE·05:59 PM
Data Sourced
via MITRE·05:59 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16221.
2
What is the severity of CVE-2018-16221?
The severity of CVE-2018-16221 is high (8.0).
3
Which software is affected by CVE-2018-16221?
The Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 is affected by CVE-2018-16221.
4
What is the vulnerability type for CVE-2018-16221?
CVE-2018-16221 is a path traversal vulnerability.
5
How can an attacker exploit CVE-2018-16221?
An authenticated remote attacker can exploit CVE-2018-16221 by using path traversal to access privileged information.