Yealink SIP-T33G 固件版本 124.86.x.x(124.87.0.0 之前)存在一个竞态条件漏洞。经过认证的(authenticated)攻击者可以通过并发删除写入到诊断目录下可预测路径中的输出文件,从而中断正在运行的诊断进程。攻击者可以触发一项诊断操作(如 traceroute 或 ping),同时调用文件删除接口来终止正在运行的进程,导致系统处于不一致的状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet