PoC Index

CVE-2014-3427

MEDIUM 5.0EPSS 5.2%

CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
5.20% chance of exploitation in the next 30 days, 92th percentile
Published
2014-07-16
Updated
2024-08-06

ExploitDB entries (1)

References

Related