CVE-2024-33109

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ergophone:tiptel_ip_286_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ergophone:tiptel_ip_286:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:yealink:sip-t28p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yealink:sip-t28p:-:*:*:*:*:*:*:*

History

25 Sep 2024, 14:47

Type Values Removed Values Added
References () https://www.bdosecurity.de/en-gb/advisories/cve-2024-33109 - () https://www.bdosecurity.de/en-gb/advisories/cve-2024-33109 - Third Party Advisory
References () http://tiptel.com - () http://tiptel.com - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:h:ergophone:tiptel_ip_286:-:*:*:*:*:*:*:*
cpe:2.3:o:ergophone:tiptel_ip_286_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:yealink:sip-t28p:-:*:*:*:*:*:*:*
cpe:2.3:o:yealink:sip-t28p_firmware:*:*:*:*:*:*:*:*
CWE CWE-22
First Time Yealink sip-t28p Firmware
Ergophone
Yealink
Ergophone tiptel Ip 286 Firmware
Yealink sip-t28p
Ergophone tiptel Ip 286

19 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-19 19:15

Updated : 2024-09-25 14:47


NVD link : CVE-2024-33109

Mitre link : CVE-2024-33109


JSON object : View

Products Affected

ergophone

  • tiptel_ip_286
  • tiptel_ip_286_firmware

yealink

  • sip-t28p
  • sip-t28p_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')