Junglewise Threat Intelligence

CVE-2026-12220: Yealink SIP-T46U stack overflow in Firmware Chunk Upload handler

CVE-2026-12220 · Severity: high · CVSS 8 · Published 2026-06-15

Technologies: Yealink SIP-T46U. Vendors: Yealink.

Executive brief

A security vulnerability exists in Yealink SIP-T46U business desk phones. An attacker on the same local network could exploit this flaw to crash the device or potentially take control of it. This could lead to a disruption of communication services or unauthorized access to the device's functions.

Technical details

A stack-based buffer overflow vulnerability exists in the Yealink SIP-T46U firmware version 108.86.0.118. The flaw is located within the mod_upgrade.SparePartsUpload function in the /api/upgrade/accupgradebychunk component. By manipulating the 'uid' argument during a firmware chunk upload request, an attacker with low-privileged access on the adjacent network can trigger the overflow. This can lead to arbitrary code execution or a complete system crash. As of the advisory date, the vendor has not responded to the disclosure, and no official patch is confirmed.

Affected products

  • Yealink SIP-T46U 108.86.0.118

Timeline

  • 2026-06-15: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-06-15: advisory

References

Related threats