Lucene search

K
cvelistMitreCVELIST:CVE-2019-14656
HistoryOct 08, 2019 - 12:01 p.m.

CVE-2019-14656

2019-10-0812:01:20
mitre
www.cve.org
3

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

53.2%

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

53.2%

Related for CVELIST:CVE-2019-14656