Yealink Forums
security issue action uri: - Printable Version

+- Yealink Forums (http://forum.yealink.com/forum)
+-- Forum: IP Phone Series (/forumdisplay.php?fid=4)
+--- Forum: Wishlist (/forumdisplay.php?fid=13)
+--- Thread: security issue action uri: (/showthread.php?tid=42272)



security issue action uri: - Chris Barron - 11-26-2018 02:45 PM

Chaps:
this is partly a security alert and partly a request for a default configuration change.
The default setting for T4 series seems to be
features.action_uri.enable = 1
it should be = 0
This leaves the phone open to the following exploitation.

The phone is registered on port 5060 behind the nat (i.e first phone to be registered)
Because the action uri is open, the attack sets callforward on the phone to an international number