PT-2026-49138 · Yealink · Sip-T46U

·

CVE-2026-12222

·

Published

2026-06-14

·

Updated

2026-06-27

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yealink SIP-T46U version 108.86.0.118
Description A stack-based buffer overflow exists in the Web FastCGI Service component within the mod webd.BlueToothTest() function of the /api/inner/bttest endpoint. This issue occurs when manipulating the btMac, pin, or reserved arguments. Exploitation requires the attacker to be located within the local network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12222

Affected Products

Sip-T46U