VYPR

T21P_E2

by Yealink

CVEs (2)

  • CVE-2025-14228LowDec 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the component Local Directory Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2025-66737Dec 26, 2025
    risk 0.00cvss epss 0.00

    Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.