CVE-2021-27561
Published Oct 15, 2021Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
- evidence mentions
- 5
- Buzz score
- 55.9
Vendor/product archive
1 CVEs tagged to yealink / device_management — 1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.