A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Jun 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection | |
| First Time appeared |
Yealink
Yealink sip-t46u |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:yealink:sip-t46u:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yealink
Yealink sip-t46u |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-15T04:30:12.020Z
Reserved: 2026-06-14T13:54:13.580Z
Link: CVE-2026-12219
No data.
Status : Received
Published: 2026-06-15T06:16:23.953
Modified: 2026-06-15T06:16:23.953
Link: CVE-2026-12219
No data.
OpenCVE Enrichment
No data.