CVE-2024-33109

CRITICAL

Tiptel IP 286 Firmware < 2.61.13.10 - Path Traversal and Arbitrary File Write via Ringtone Upload

Title source: llm
STIX 2.1

Description

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

References (2)

Core 2

Scores

CVSS v3 9.9
EPSS 0.0086
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
ergophone/tiptel_ip_286_firmware < 2.61.13.10
yealink/sip-t28p_firmware < 2.61.13.10
Published Sep 19, 2024
Tracked Since Feb 18, 2026