Executive brief
A security vulnerability exists in the Yealink SIP-T46U IP phone, a device commonly used for business telecommunications. An attacker on the same local network could exploit this flaw to crash the device or potentially take control of it. This could lead to a disruption of phone services or unauthorized access to the device's functions.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the Yealink SIP-T46U firmware version 108.86.0.118. The flaw is located within the mod_webd.BlueToothTest function in the /api/inner/bttest endpoint of the Web FastCGI Service. By manipulating the btMac, pin, or reserved arguments, an attacker with low privileges on the local network can trigger the overflow. This can lead to full system compromise (confidentiality, integrity, and availability impact). As of the advisory date, the vendor has not responded to disclosure attempts, and an exploit has been publicly released.
Affected products
- Yealink SIP-T46U 108.86.0.118
Timeline
- 2026-06-15: disclosed: Public disclosure of the vulnerability and exploit
- 2026-06-15: advisory: CVE-2026-12222 published to NVD