Loading
CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.
Use Yealink vendor hub and Voip Phone Firmware product page to widen CVE-2014-3427 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-3428 for nearby disclosures in the same product family.