← Back to CVE List

CVE-2019-14656

Published: 2019-10-08T13:15Z
Last Modified: 2024-11-21T04:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt