CVE-2014-3428
Yealink Voip Phone Firmware - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet.
References (4)
Scores
EPSS
0.0026
EPSS Percentile
48.7%
Details
CWE
CWE-79
Status
published
Products (3)
yealink/voip_phone_firmware
yealink/voip_phone
n/a/n/a
Published
Jun 16, 2014
Tracked Since
Feb 18, 2026