CVE-2014-3427
16.07.2014, 14:19
CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.Enginsight
| Vendor | Product | Version |
|---|---|---|
| yealink | voip_phone_firmware | 28.72.0.2 |
𝑥
= Vulnerable software versions
References