Executive brief
A security vulnerability has been identified in Yealink SIP-T46U business desk phones. An attacker on the same local network could potentially execute unauthorized commands on the device by manipulating network diagnostic settings. This could lead to unauthorized access to the phone's functions or disruption of communication services.
Technical details
A command injection vulnerability exists in the Yealink SIP-T46U firmware version 108.86.0.118. The flaw is located within the mod_webd.TFTPUploadIperf function of the Web FastCGI Service, specifically in the /api/inner/tftpuploadiperf endpoint. By manipulating the 'ip' or 'port' arguments, an attacker with low privileges and local network access can inject and execute arbitrary system commands. The vulnerability stems from improper neutralization of special elements used in a command (CWE-77). As of the disclosure date, the vendor has not provided a patch or response.
Affected products
- Yealink SIP-T46U 108.86.0.118
Timeline
- 2026-06-15: disclosed: Vulnerability disclosed via VulDB and NVD
- 2026-06-15: advisory