Vulnerability Details CVE-2024-33109
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.2%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2024-33109
-
cpe:2.3:h:ergophone:tiptel_ip_286:-
-
cpe:2.3:h:yealink:sip-t28p:-
-
cpe:2.3:o:ergophone:tiptel_ip_286_firmware:*
-
cpe:2.3:o:yealink:sip-t28p_firmware:-
-
cpe:2.3:o:yealink:sip-t28p_firmware:2.61.13.10