CyberRota Analysis
AI analysis pending.
CVE
CVE-2019-14656
Severity
HIGH
CVSS
8.8
EPSS
1.98%
Original NVD Description
Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.