CSRF Vulnerability in Yealink Ultra-elegant IP Phone SIP-T41P
CVE-2018-16218
8.8HIGH
What is CVE-2018-16218?
A vulnerability exists in the web interface of the Yealink Ultra-elegant IP Phone SIP-T41P, specifically in firmware version 66.83.0.35. This security flaw allows remote attackers to exploit the device by crafting a malicious link that, when clicked by a victim, can facilitate unauthorized code execution or alteration of device settings. Such exploitation could lead to significant security risks for users, as sensitive configurations might be compromised without the user's consent.