Executive brief
A security vulnerability exists in the Yealink SIP-T46U business IP phone. An attacker on the same local network can exploit this flaw to potentially take full control of the device or cause it to crash. This could lead to unauthorized access to communication data or a complete disruption of phone services.
Technical details
A stack-based buffer overflow vulnerability exists in the Yealink SIP-T46U firmware version 108.86.0.118. The flaw is located within the 'sprintf' function call in the '/api/upgrade/upgrade' file, specifically within the Firmware Chunk Upload Handler component. An attacker can trigger the overflow by manipulating the 'uid' or 'start_offset' arguments during a firmware upload request. Exploitation requires access to the adjacent network and low-level privileges. Successful exploitation could lead to arbitrary code execution or a device crash. A public exploit is reportedly available, and the vendor has not yet provided a patch.
Affected products
- Yealink SIP-T46U 108.86.0.118
Timeline
- 2026-06-15: disclosed
- 2026-06-15: advisory: NVD publication date