CVE-2019-14656: Malicious File Upload
Published Oct 8, 2019
·Updated
Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.
Affected Software
6 affected components
Yeahlink Vp59 Firmware<=2019-08-04
Yeahlink Vp59
Yeahlink T49g Firmware<=2019-08-04
Yeahlink T49g
Yeahlink T58v Firmware<=2019-08-04
Yeahlink T58v
Event History
Oct 8, 2019
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14656?
CVE-2019-14656 is rated as a critical vulnerability due to the potential for unauthorized administrative access.
2
How do I fix CVE-2019-14656?
To mitigate CVE-2019-14656, update the affected Yealink firmware to a version released after August 4, 2019.
3
Which Yealink devices are impacted by CVE-2019-14656?
CVE-2019-14656 affects Yealink VP59, T49G, and T58V devices running firmware versions prior to 2019-08-04.
4
What are the implications of CVE-2019-14656?
CVE-2019-14656 allows a default user account to perform admin-level actions, posing significant security risks.
5
Is there a workaround for CVE-2019-14656?
A temporary workaround for CVE-2019-14656 includes disabling remote management to limit unauthorized access.