Skip to main content

Vendor archive

yealink CVEs

Beta · best-effort

24 CVEs tagged to vendor yealink7 Critical, 9 High, 6 Medium, 2 Low, 0 Unrated.

CVE-2024-48353

Published Nov 1, 2024

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48352

Published Nov 1, 2024

Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31747

Published Apr 29, 2024

An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximate attacker to disable the phone lock via the Walkie Talkie…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30939

Published Apr 25, 2024

An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28442

Published Mar 26, 2024

Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company por…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24681

Published Feb 23, 2024

An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24113

Published Aug 22, 2023

Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of servic…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27561

Published Oct 15, 2021

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
55.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2013-5758

Published Aug 3, 2014

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demo…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-5757

Published Aug 3, 2014

Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function i…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5756

Published Aug 3, 2014

Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiS…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3427

Published Jul 16, 2014

CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5755

Published Jul 16, 2014

config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) v…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1