Логотип exploitDog
bind:CVE-2019-14656
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-14656

Количество 2

Количество 2

nvd логотип

CVE-2019-14656

около 6 лет назад

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22wm-vgh4-2j44

больше 3 лет назад

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-14656

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

CVSS3: 8.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-22wm-vgh4-2j44

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу