Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-43959. PoCs published by tahaafarooq.
AI-analyzed exploit summary This exploit demonstrates an authenticated command injection vulnerability in YeaLink SIP-TXXXP 53.84.0.15 via the diagnostic tool's 'cmd' parameter. The PoC sends a crafted POST request to execute arbitrary commands (e.g., 'id') and retrieves the output in the HTTP response.
Description
An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
Exploits (1)
This exploit demonstrates an authenticated command injection vulnerability in YeaLink SIP-TXXXP 53.84.0.15 via the diagnostic tool's 'cmd' parameter. The PoC sends a crafted POST request to execute arbitrary commands (e.g., 'id') and retrieves the output in the HTTP response.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H