Executive brief
A security vulnerability has been identified in Yealink SIP-T46U business IP phones. This flaw allows a remote attacker to execute unauthorized commands on the device by manipulating diagnostic settings. If exploited, an attacker could gain control over the phone, potentially leading to unauthorized access to communications or disruption of phone services.
Technical details
A command injection vulnerability exists in the Web FastCGI Service of Yealink SIP-T46U firmware version 108.86.0.118. The flaw is located within the mod_diagnose.CommandShellByType function in the /api/diagnosis/start component. An attacker can trigger this vulnerability by providing a specially crafted 'Time' argument, which is improperly neutralized before being passed to a system shell. Exploitation requires network access and low-level authentication (PR:L). Successful exploitation allows for remote code execution on the device. As of the advisory date, the vendor has not provided a patch.
Affected products
- Yealink SIP-T46U 108.86.0.118
Timeline
- 2026-06-15: disclosed
- 2026-06-15: advisory: NVD publication date