CVE-2026-12219: Command Injection in Yealink SIP-T46U
A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. Upgrading to version 108.87.0.23 is sufficient to resolve this issue. It is advisable to upgrade the affected component.
AI Analysis
Technical Summary
A command injection vulnerability exists in Yealink SIP-T46U version 108.86.0.118 within the mod_diagnose.CommandShellByType function of the /api/diagnosis/start API endpoint in the Web FastCGI Service. The vulnerability arises from improper handling of the Time argument, allowing remote attackers to execute arbitrary commands. An exploit has been published. Upgrading to version 108.87.0.23 mitigates the issue.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary commands on the affected device, potentially compromising device integrity and confidentiality. The vulnerability has a medium severity score of 5.3, reflecting the network attack vector with low complexity and no user interaction required. The impact on confidentiality, integrity, and availability is low to limited.
Mitigation Recommendations
Upgrade the Yealink SIP-T46U device from version 108.86.0.118 to version 108.87.0.23 to remediate this vulnerability. This upgrade fully resolves the command injection issue. No additional mitigations are indicated by the vendor advisory.
CVE-2026-12219: Command Injection in Yealink SIP-T46U
Description
A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. Upgrading to version 108.87.0.23 is sufficient to resolve this issue. It is advisable to upgrade the affected component.
CVSS v4.0
Score 5.3medium
Affected software
cpe:2.3:a:yealink:sip-t46u:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A command injection vulnerability exists in Yealink SIP-T46U version 108.86.0.118 within the mod_diagnose.CommandShellByType function of the /api/diagnosis/start API endpoint in the Web FastCGI Service. The vulnerability arises from improper handling of the Time argument, allowing remote attackers to execute arbitrary commands. An exploit has been published. Upgrading to version 108.87.0.23 mitigates the issue.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary commands on the affected device, potentially compromising device integrity and confidentiality. The vulnerability has a medium severity score of 5.3, reflecting the network attack vector with low complexity and no user interaction required. The impact on confidentiality, integrity, and availability is low to limited.
Mitigation Recommendations
Upgrade the Yealink SIP-T46U device from version 108.86.0.118 to version 108.87.0.23 to remediate this vulnerability. This upgrade fully resolves the command injection issue. No additional mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-14T13:54:13.580Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2f96421cccde5f260cd67b
Added to database: 06/15/2026, 06:05:54 UTC
Last enriched: 06/29/2026, 21:10:46 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 246
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.