QSearchQSearch

CVE-2026-12221

8.0 HIGH

A vulnerability was found in Yealink SIP-T46U 108.86.0.118

Published: 2026-06-15 · Last updated: 2026-06-15

Severity and scoring

CVSS
8.0 HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-119, CWE-121

Description

A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The attack needs to be approached within the local network. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-7273 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allo... (8.8 HIGH)
  • CVE-2025-55660 A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of... (5.5 MEDIUM)
  • CVE-2026-8356 LibreOffice can import presentations in the legacy binary PPT format
  • CVE-2026-12222 A vulnerability was determined in Yealink SIP-T46U 108.86.0.118 (8.0 HIGH)
  • CVE-2026-12220 A vulnerability has been found in Yealink SIP-T46U 108.86.0.118 (8.0 HIGH)