Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sip T21\(p\)e2 Firmware HIGH 8.8
CVE-2025-66738

An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping func…

No fix yet
Fix from $1,950 2025-12-26
Yealink Meeting Server HIGH 7.5
CVE-2024-48353

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwor…

Fix: 26.0.0.67+
Fix from $1,950 2024-11-01
Yealink Meeting Server HIGH 7.5
CVE-2024-48352

Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

Fix: 26.0.0.67+
Fix from $1,950 2024-11-01
Vp59 Firmware MEDIUM 6.8
CVE-2024-30939

An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an acc…

No fix yet
Fix from $1,600 2024-04-25
Vp59 Firmware HIGH 7.5
CVE-2024-28442

Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of u…

No fix yet
Fix from $1,950 2024-03-26
Configuration Encryption Tool CRITICAL 9.8
CVE-2024-24681

An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is…

Fix: 1.2+
Fix from $2,300 2024-02-23
Configuration Encryption Tool HIGH 7.5
CVE-2022-48625

Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

Fix: 1.2+
Fix from $1,950 2024-02-20
Yealink Meeting Server CRITICAL 9.8
CVE-2024-24091

Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

Fix: 26.0.0.66+
Fix from $2,300 2024-02-08
Sip T19p E2 Firmware HIGH 8.8
CVE-2023-43959

An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of …

No fix yet
Fix from $1,950 2023-10-17
W60b Firmware CRITICAL 9.1
CVE-2020-24113

Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive informatio…

Mitigation only
Fix from $2,300 2023-08-22
Device Management CRITICAL 9.8
CVE-2021-27561 KEVEPSS 83%

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

Fix: after 3.6.0.20
Fix from $2,300 2021-10-15
Ultra Elegant Ip Phone Sip T41p Firmware HIGH 8.8
CVE-2018-16217

The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker t…

Mitigation only
Fix from $1,950 2019-05-29
Ultra Elegant Ip Phone Sip T41p Firmware HIGH 8.8
CVE-2018-16218

A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote …

No fix yet
Fix from $1,950 2019-05-29
Ultra Elegant Ip Phone Sip T41p Firmware HIGH 8.0
CVE-2018-16221

The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (…

Mitigation only
Fix from $1,950 2019-05-29
Sip T38g HIGH 9.0
CVE-2013-5758EPSS 12%

cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in …

No fix yet
Fix from $1,950 2014-08-03
Sip T38g HIGH 10.0
CVE-2013-5755

config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) fo…

Mitigation only
Fix from $1,950 2014-07-16
Voip Phone Firmware MEDIUM 5.0
CVE-2014-3427EPSS 5%

CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP…

No fix yet
Fix from $1,600 2014-07-16