Critical severity9.8CISA KEVNVD Advisory· Published Oct 15, 2021· Updated Jun 17, 2026
CVE-2021-27561
CVE-2021-27561
Description
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:yealink:device_management:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:yealink:device_management:*:*:*:*:*:*:*:*range: <=3.6.0.20
- (no CPE)range: = 3.6.0.20
- Yealink/Device Managementdescription
Patches
Vulnerability mechanics
References
2- ssd-disclosure.comnvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.