CVE-2024-33109
19.09.2024, 19:15
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
| Vendor | Product | Version |
|---|---|---|
| ergophone | tiptel_ip_286_firmware | 𝑥 ≤ 2.61.13.10 |
| yealink | sip-t28p_firmware | 𝑥 ≤ 2.61.13.10 |
𝑥
= Vulnerable software versions