CVE detail
CVE-2018-16218 — CVE-2018-16218
Published 2019-05-29 · Modified 2026-06-17 · Vendor yealink · Product ultra-elegant_ip_phone_sip-t41p_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0126
EPSS probability
exploitation probability, 30d
67.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote attacker to trigger code execution or settings modification on the device by providing a crafted link to the victim.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References