Critical severity9.8NVD Advisory· Published Feb 23, 2024· Updated Jun 17, 2026
CVE-2024-24681
CVE-2024-24681
Description
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:yealink:configuration_encryption_tool:*:*:*:*:rsa:*:*:*+ 1 more
- cpe:2.3:a:yealink:configuration_encryption_tool:*:*:*:*:rsa:*:*:*range: <1.2
- cpe:2.3:a:yealink:configuration_encryption_tool:-:*:*:*:aes:*:*:*
- Yealink/Configuration Encrypt Tooldescription
Patches
Vulnerability mechanics
References
3- github.com/gitaware/CVE/tree/main/CVE-2024-24681nvdThird Party Advisory
- seclists.org/fulldisclosure/2024/Feb/22nvdMailing List
- seclists.org/fulldisclosure/2024/Feb/22nvd
News mentions
0No linked articles in our index yet.