CVE-2026-12218 PUBLISHED

Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflow

Assigner: VulDB
Reserved: 14.06.2026 Published: 15.06.2026 Updated: 15.06.2026

A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local network is required for this attack. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 8.6

Product Status

Vendor Yealink
Product SIP-T46U
Versions
  • Version 108.87.50.1 is affected

Credits

  • CookedMelon (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Stack-based Buffer Overflow CWE
  • Memory Corruption CWE