CVE-2012-1417
UnknownEPSS 1.73%
Last modified
CVE-2012-1417 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yealink | Gigabit Color Ip Phone Sip-T32g | All versions |
| Yealink | Gigabit Color Ip Phone Sip-T38g | All versions |
| Yealink | Ip Phone Sip-T19p | All versions |
| Yealink | Ip Phone Sip-T20p | All versions |
| Yealink | Ip Phone Sip-T21p | All versions |
| Yealink | Ip Phone Sip-T22p | All versions |
| Yealink | Ip Phone Sip-T26p | All versions |
| Yealink | Ip Phone Sip-T28p | All versions |
| Yealink | Ip Video Phone Vp530 | All versions |
| Yealink | Ultra-Elegant Ip Phone Sip-T41p | All versions |
| Yealink | Ultra-Elegant Ip Phone Sip-T42g | All versions |
| Yealink | Ultra-Elegant Ip Phone Sip-T46g | All versions |
| Yealink | Ultra-Elegant Ip Phone Sip-T48g | All versions |
| Yealink | W52p | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1417?
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.
How severe is CVE-2012-1417?
Severity scoring for CVE-2012-1417 is pending analysis. The EPSS model estimates a 1.73% probability of exploitation in the next 30 days.
How do I fix CVE-2012-1417?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-1409Unspecified vulnerability in the Tiny Password (com.tinycouc…
- CVE-2012-1410Multiple cross-site scripting (XSS) vulnerabilities in the H…
- CVE-2012-1413Cross-site scripting (XSS) vulnerability in zc_install/inclu…
- CVE-2012-1414Cross-site request forgery (CSRF) vulnerability in manager/n…
- CVE-2012-1415Cross-site request forgery (CSRF) vulnerability in lib/logou…
- CVE-2012-1416Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2012-1418Multiple unspecified vulnerabilities in Google Chrome before…
- CVE-2012-1419The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat…
- CVE-2012-1420The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00,…
- CVE-2012-1421The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00,…
- CVE-2012-1422The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00,…
- CVE-2012-1423The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft …
Are you affected by CVE-2012-1417?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
