VYPR

Configuration Encryption Tool

by Yealink

CVEs (2)

  • CVE-2024-24681CriFeb 23, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.

  • CVE-2022-48625HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.00

    Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.