Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Chichen241

#19526of 53,622
13.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-49182
5.5
2026-06-15
Yealink · Sip-T46U · CVE-2026-12223
**Name of the Vulnerable Software and Affected Versions** Yealink SIP-T46U version 108.86.0.118 **Description** Command injection is possible in the Web FastCGI Service via the `mod webd.TFTPUploadIperf` function within the '/api/inner/tftpuploadiperf' endpoint. This occurs when the `ip/port` argument is manipulated. The attack must be initiated from within the local network. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-49138
8.0
2026-06-14
Yealink · Sip-T46U · CVE-2026-12222
**Name of the Vulnerable Software and Affected Versions** Yealink SIP-T46U version 108.86.0.118 **Description** A stack-based buffer overflow exists in the Web FastCGI Service component within the `mod webd.BlueToothTest()` function of the `/api/inner/bttest` endpoint. This issue occurs when manipulating the `btMac`, `pin`, or `reserved` arguments. Exploitation requires the attacker to be located within the local network. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.