Vulnerabilities
Vulnerable Software
Yealink:  Security Vulnerabilities
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-11-01
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
CVSS Score
7.5
EPSS Score
0.0
Published
2024-11-01
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
CVSS Score
9.9
EPSS Score
0.005
Published
2024-09-19
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-02-23
Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-02-20
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
CVSS Score
9.8
EPSS Score
0.009
Published
2024-02-08
An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
CVSS Score
8.8
EPSS Score
0.08
Published
2023-10-17
Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).
CVSS Score
9.1
EPSS Score
0.003
Published
2023-08-22
CVE-2021-27561
Known exploited
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
CVSS Score
9.8
EPSS Score
0.941
Published
2021-10-15
The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker to trigger OS commands or open a reverse shell via command injection.
CVSS Score
8.8
EPSS Score
0.072
Published
2019-05-29


Contact Us

Shodan ® - All rights reserved