yealink
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting yealink.
- CVE-2026-12223Yealink SIP-T46U Web FastCGI Service tftpuploadiperf mod_webd.TFTPUploadIperf command injection5.5
- CVE-2026-12222Yealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflow8.0
- CVE-2026-12221Yealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflow8.0
- CVE-2026-12220Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflow8.0
- CVE-2026-12219Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection6.3
- CVE-2026-12218Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflow8.0
- CVE-2026-1735Yealink MeetingBar A30 Diagnostic command injection4.3
- CVE-2025-66737Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic comp...4.3
- CVE-2025-66738An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.8.8
- CVE-2025-68644Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to...7.4
- CVE-2025-14228Yealink SIP-T21P E2 Local Directory cross site scripting3.5
- CVE-2025-52918Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.5.0
- CVE-2025-52919In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.4.3
- CVE-2025-52916Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).2.2
- CVE-2025-52917The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.4.3