CVE-2024-33109

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/09/2024
Last modified:
25/09/2024

Description

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ergophone:tiptel_ip_286_firmware:*:*:*:*:*:*:*:* 2.61.13.10 (including)
cpe:2.3:h:ergophone:tiptel_ip_286:-:*:*:*:*:*:*:*
cpe:2.3:o:yealink:sip-t28p_firmware:*:*:*:*:*:*:*:* 2.61.13.10 (including)
cpe:2.3:h:yealink:sip-t28p:-:*:*:*:*:*:*:*