Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.
                
            References
                    | Link | Resource | 
|---|---|
| https://medium.com/%40deepsahu1/cve-2024-28442-yealink-ip-phone-webview-escape-leads-to-sensitive-file-disclosure-via-directory-686ef8f80227 | Exploit Third Party Advisory Permissions Required | 
| https://www.yealink.com/en/product-detail/ip-phone-vp59 | Product | 
| https://medium.com/%40deepsahu1/cve-2024-28442-yealink-ip-phone-webview-escape-leads-to-sensitive-file-disclosure-via-directory-686ef8f80227 | Exploit Third Party Advisory Permissions Required | 
| https://www.yealink.com/en/product-detail/ip-phone-vp59 | Product | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    30 Jul 2025, 00:24
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://medium.com/%40deepsahu1/cve-2024-28442-yealink-ip-phone-webview-escape-leads-to-sensitive-file-disclosure-via-directory-686ef8f80227 - Exploit, Third Party Advisory, Permissions Required | |
| References | () https://www.yealink.com/en/product-detail/ip-phone-vp59 - Product | |
| CPE | cpe:2.3:o:yealink:vp59_firmware:91.15.0.118:*:*:*:*:*:*:* cpe:2.3:h:yealink:vp59:-:*:*:*:*:*:*:* | |
| First Time | Yealink vp59 Yealink vp59 Firmware Yealink | 
21 Nov 2024, 09:06
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://medium.com/%40deepsahu1/cve-2024-28442-yealink-ip-phone-webview-escape-leads-to-sensitive-file-disclosure-via-directory-686ef8f80227 - | |
| References | () https://www.yealink.com/en/product-detail/ip-phone-vp59 - | 
05 Aug 2024, 17:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-200 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.5 | 
26 Mar 2024, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-03-26 20:15
Updated : 2025-07-30 00:24
NVD link : CVE-2024-28442
Mitre link : CVE-2024-28442
CVE.ORG link : CVE-2024-28442
JSON object : View
Products Affected
                yealink
- vp59_firmware
- vp59
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
