CVE-2024-33109
19.09.2024, 19:15
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
Vendor | Product | Version |
---|---|---|
ergophone | tiptel_ip_286_firmware | 𝑥 ≤ 2.61.13.10 |
yealink | sip-t28p_firmware | 𝑥 ≤ 2.61.13.10 |
𝑥
= Vulnerable software versions