Cross-Site Scripting Vulnerability in Yealink VoIP Phones
CVE-2014-3428

Currently unrated

Key Information:

Vendor

Yealink

Vendor
CVE Published:
16 June 2014

What is CVE-2014-3428?

Yealink VoIP Phones running firmware version 28.72.0.2 are susceptible to a cross-site scripting vulnerability that enables remote attackers to execute arbitrary web scripts or HTML. This weakness arises from improper validation of input in the model parameter to the servlet, allowing unauthorized entities to manipulate the device's web interface, potentially leading to further exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.