Skip to main content

Vendor/product archive

yealink / device_management CVEs

Beta · best-effort

1 CVEs tagged to yealink / device_management1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-27561

Published Oct 15, 2021

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
55.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1