VYPR

phones

by Yealink

CVEs (8)

  • CVE-2019-14657HigOct 8, 2019
    risk 0.57cvss 8.8epss 0.04

    Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password…

  • CVE-2019-14656HigOct 8, 2019
    risk 0.57cvss 8.8epss 0.02

    Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

  • CVE-2025-52918MedJun 21, 2025
    risk 0.33cvss 5.0epss 0.00

    Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.

  • CVE-2025-52919MedJun 21, 2025
    risk 0.28cvss 4.3epss 0.00

    In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.

  • CVE-2025-52917MedJun 21, 2025
    risk 0.28cvss 4.3epss 0.00

    The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.

  • CVE-2025-52916LowJun 21, 2025
    risk 0.14cvss 2.2epss 0.00

    Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).

  • CVE-2014-3427Jul 16, 2014
    risk 0.03cvss epss 0.05

    CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.

  • CVE-2014-3428Jun 16, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet.