Impact
A stack-based buffer overflow exists in the Firmware Chunk Upload handler of Yealink SIP-T46U, specifically within the mod_upgrade.SparePartsUpload function. Manipulating the uid argument in the /api/upgrade/accupgradebychunk API can corrupt the stack, allowing an attacker to execute arbitrary code on the device. The flaw could be exploited to gain elevated privileges or take full control of the unit once the overflow is triggered.
Affected Systems
The vulnerability affects Yealink SIP-T46U units running firmware version 108.86.0.118. No other versions or related Yealink products are listed as impacted in the current data.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity; the attack requires local network access and relies on the target device processing a crafted request to the vulnerable endpoint. The EPSS score is not available, and the flaw is not listed in CISA KEV. Because the exploit is publicly disclosed, an attacker with local network presence could initiate the overflow, resulting in potentially full device compromise.
OpenCVE Enrichment