CVE-2024-28442: Infoleak
Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28442?
CVE-2024-28442 is considered a medium severity vulnerability due to its potential for sensitive information disclosure.
What type of vulnerability is CVE-2024-28442?
CVE-2024-28442 is a directory traversal vulnerability that allows unauthorized access to sensitive files.
Who is affected by CVE-2024-28442?
The vulnerability affects users of Yealink VP59 running firmware version 91.15.0.118.
How do I fix CVE-2024-28442?
To fix CVE-2024-28442, users should update their Yealink VP59 devices to the latest firmware version released by Yealink.
What can an attacker do with CVE-2024-28442?
An attacker with physical proximity can exploit CVE-2024-28442 to gain access to sensitive information through the terms of use function.