Yealink IP Phone WEB Server Vulnerabilities

CVE Dictionary Entry: CVE-2018-16221, CVE-2018-16218, CVE-2018-16217

DATE PUBLISHED: 2019-05-29

Please Note: Yealink takes the security of our customers and our products seriously. This is a living document and may be subject to updates. The latest version of this document can be found at the following URL: https://www.yealink.com/trust-center-resource

Vulnerability Summary

The diagnostics web interface in the Yealink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal). This allows an authenticated remote attacker to gain access to privileged information (e.g., /etc/passwd) via path traversal, using relative path information in the file parameter of the corresponding POST request.

Solution

Yealink has released software updates to all affected phone models that contain fixes for these issues, as well as other fixes and features. Please refer to the release notes for your particular endpoint for more information.

Phone Series:

Product Family and ModelFixed Software Release
SIP-T27P45.83.0.120
SIP-T29G46.83.0.120
SIP-T41P36.83.0.120
SIP-T42G29.83.0.120
SIP-T46G28.83.0.120
SIP-T48G35.83.0.120
SIP-T19P_E253.84.0.130
SIP-T21P_E252.84.0.130
SIP-T23G44.84.0.130
SIP-T40P54.84.0.130
SIP-T40G76.84.0.130
SIP-T52S/T54S70.84.0.80
SIP-CP92078.86.0.15
T4XS Series Phones66.86.0.15
T4XU Series Phones108.86.0.60
T3X Series Phones124.86.0.60
T5X Series Phones96.86.0.60
SIP-T5858.86.0.5
SIP-CP96073.86.0.5
SIP-VP5991.86.0.5
SIP-T58W150.86.0.35
SIP-CP965143.86.0.5
VP59-Zoom91.30.0.30
MP5X-Zoom122.30.0.15
MP5X-Teams122.15.0.9
T5X-Teams58.15.0.53
CP960-Teams73.15.0.163
CP965-Teams143.15.0.12

VCS Series:

Product Family and ModelFixed Software Release
VC210 Series118.320.0.15
MeetingEye400 Series120.320.0.15
MeetingEye400Pro Series133.320.0.15
MeetingEye800 Series129.320.0.30
VP59-VCS91.353.0.10
CTP18137.353.0.15
MeetingBarA20/A30133.15.0.105
MeetingBoard65155.310.0.15
RoomPanel147.15.0.33
RoomCast144.312.0.5

The software, release notes, and other documentation for your voice endpoint can be found at: https://support.yealink.com/en/portal/home

Mitigation

Yealink recommends all customers upgrade to the latest version. ✔️

Contact

Any customer using an affected system who is concerned about this vulnerability within their deployment should contact Yealink Technical Support by visiting: https://support.yealink.com/en/portal/home for the latest information.

You might also find value in the high-level security guidance and security news located at: https://support.yealink.com/en/portal/home


File Info : application/pdf, 3 Pages, 245.96KB

PDF preview unavailable. Download the PDF instead.

202305310637056576ad178b145d582b5428fcdee8a15

References

Microsoft Word 2016 Microsoft Word 2016

Related Documents

Preview Yealink IP Phone Recovery Mode Guide
This guide provides step-by-step instructions for restoring Yealink IP phones and video conferencing systems to their default state using the TFTP recovery mode. It details the necessary firmware files, TFTP server configuration, and specific procedures for various Yealink product series.
Preview Yealink SIP-TxP/T3xG Series BroadWorks Partner Configuration Guide
This guide details the configuration procedures for Yealink SIP-TxP/T3xG series IP phones to integrate with the BroadWorks platform, covering interoperability, device management, and advanced feature setup.
Preview Yealink SIP IP Phones Administrator Guide for T2, T4, T5 Series & CP920
Comprehensive guide for Yealink SIP IP phones (T2, T4, T5 Series, CP920), detailing network setup, provisioning, security, troubleshooting, and feature configuration for administrators.
Preview Yealink T5 Series/CP960 IP Phones Administrator Guide
Comprehensive administrator guide for Yealink T5 Series and CP960 IP Phones, covering network setup, provisioning, customization, firmware upgrades, and troubleshooting for efficient deployment and management.
Preview Yealink SIP-T31/T31P/T31G Classic IP Phone Quick Start Guide
This guide provides essential information for setting up and using the Yealink SIP-T31, SIP-T31P, and SIP-T31G Classic IP Phones. Learn about package contents, assembly, network and power connections, startup procedures, and basic phone configurations via web or user interface.
Preview Yealink SIP-T31, T31P, T31G Classic IP Phone Quick Start Guide
A concise quick start guide for Yealink SIP-T31, T31P, and T31G Classic IP Phones, covering package contents, assembly, network and power connections, phone configuration via web or UI, and essential call operations like placing, answering, holding, transferring, and conferencing.
Preview Yealink SIP-T53 & SIP-T53W Prime Business Phone Quick Start Guide
Get started quickly with the Yealink SIP-T53 and SIP-T53W Prime Business Phones. This guide provides essential setup and configuration information for these advanced IP phones.
Preview Yealink SIP-T53 & SIP-T53W Quick Start Guide
This guide helps users set up and operate the Yealink SIP-T53 and SIP-T53W business IP phones, covering assembly, configuration, call functions, and customization.