CVE-2024-28442

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/03/2024
Last modified:
30/07/2025

Description

Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:yealink:vp59_firmware:91.15.0.118:*:*:*:*:*:*:*
cpe:2.3:h:yealink:vp59:-:*:*:*:*:*:*:*