hackmd.io
https://hackmd.io/%40tahaafarooq/auth_rce_voip CVE-2023-43959
HIGH
YeaLink SIP-TXXXP 53.84.0.15 - 'cmd' Command Injection (Authenticated)
Record summary
CVE-2023-43959 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
sip-t19p-e2_firmwareBrowse yealink / sip-t19p-e2_firmwareDefault status: unknown | CVE List | 53.84.0.15 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBYeaLink SIP-TXXXP 53.84.0.15 - 'cmd' Command Injection (Authenticated)ExploitDB exploitby tahaafarooqNot analyzed1 file
References
4hackmd.io
https://hackmd.io/@tahaafarooq/auth_rce_voip nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-43959 exploit-db.com
https://www.exploit-db.com/exploits/50509