Junglewise Threat Intelligence

CVE-2026-12218: Yealink SIP-T46U stack-based buffer overflow in Web FastCGI Service

CVE-2026-12218 · Severity: high · CVSS 8 · Published 2026-06-15

Technologies: Yealink SIP-T46U. Vendors: Yealink.

Executive brief

A security vulnerability has been identified in Yealink SIP-T46U business desk phones. An attacker on the same local network could exploit this flaw to crash the device or potentially take control of it. This could lead to unauthorized access to communication data or a complete disruption of phone services. The manufacturer was notified but has not yet provided a fix.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Yealink SIP-T46U firmware version 108.87.50.1. The vulnerability is located within the StartReportInformation function of the /api/inner/beforewifitest file, which is part of the Web FastCGI Service component. An attacker with local network access can trigger the overflow by manipulating the 'port' argument. Successful exploitation could lead to remote code execution or a denial-of-service (DoS) condition. While the vendor was contacted, no patch has been confirmed at this time, and public exploit code is reportedly available.

Affected products

  • Yealink SIP-T46U 108.87.50.1

Timeline

  • 2026-06-15: disclosed: Public disclosure of the vulnerability and exploit code.
  • 2026-06-15: advisory: NVD published the CVE record.

References

Related threats