AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-16221

HIGH · CVSS 8 EPSS 1.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-05-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-16221
Severity
HIGH
CVSS
8
EPSS
1.50%

Original NVD Description

The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).