First published: Tue Mar 26 2024(Updated: )
Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yealink VP59 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28442 is considered a medium severity vulnerability due to its potential for sensitive information disclosure.
CVE-2024-28442 is a directory traversal vulnerability that allows unauthorized access to sensitive files.
The vulnerability affects users of Yealink VP59 running firmware version 91.15.0.118.
To fix CVE-2024-28442, users should update their Yealink VP59 devices to the latest firmware version released by Yealink.
An attacker with physical proximity can exploit CVE-2024-28442 to gain access to sensitive information through the terms of use function.