Vulnerabilities (CVE)

Filtered by vendor Yealink Subscribe
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-66738 1 Yealink 2 Sip-t21\(p\)e2, Sip-t21\(p\)e2 Firmware 2026-01-09 N/A 8.8 HIGH
An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
CVE-2025-66737 1 Yealink 2 Sip-t21\(p\)e2, Sip-t21\(p\)e2 Firmware 2026-01-09 N/A 4.3 MEDIUM
Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.
CVE-2024-48353 1 Yealink 1 Yealink Meeting Server 2025-03-07 N/A 7.5 HIGH
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
CVE-2024-48352 1 Yealink 1 Yealink Meeting Server 2024-11-05 N/A 7.5 HIGH
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.