Junglewise Threat Intelligence

CVE-2026-12223: Yealink SIP-T46U command injection in Web FastCGI Service

CVE-2026-12223 · Severity: medium · CVSS 5.5 · Published 2026-06-15

Technologies: Yealink SIP-T46U. Vendors: Yealink.

Executive brief

A security vulnerability has been identified in Yealink SIP-T46U business desk phones. An attacker on the same local network could potentially execute unauthorized commands on the device by manipulating network diagnostic settings. This could lead to unauthorized access to the phone's functions or disruption of communication services.

Technical details

A command injection vulnerability exists in the Yealink SIP-T46U firmware version 108.86.0.118. The flaw is located within the mod_webd.TFTPUploadIperf function of the Web FastCGI Service, specifically in the /api/inner/tftpuploadiperf endpoint. By manipulating the 'ip' or 'port' arguments, an attacker with low privileges and local network access can inject and execute arbitrary system commands. The vulnerability stems from improper neutralization of special elements used in a command (CWE-77). As of the disclosure date, the vendor has not provided a patch or response.

Affected products

  • Yealink SIP-T46U 108.86.0.118

Timeline

  • 2026-06-15: disclosed: Vulnerability disclosed via VulDB and NVD
  • 2026-06-15: advisory

References

Related threats