CVE-2019-14657: Path Traversal
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password replacement and arbitrary code execution as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14657?
CVE-2019-14657 is considered to have a high severity due to the potential for arbitrary file replacement on Yealink phones.
How do I fix CVE-2019-14657?
To fix CVE-2019-14657, upgrade the firmware of your Yealink devices to a version released after August 4, 2019.
What types of devices are affected by CVE-2019-14657?
CVE-2019-14657 affects specific Yealink phone models, including VP59, T49G, and T58V with firmware versions up to 2019-08-04.
What are the potential consequences of CVE-2019-14657?
The exploitation of CVE-2019-14657 can lead to unauthorized access, allowing attackers to replace critical files and potentially compromise the device's security.
Is CVE-2019-14657 remotely exploitable?
Yes, CVE-2019-14657 is remotely exploitable, as it involves file upload vulnerabilities that can be triggered without physical access to the device.