Home
HIGH: 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NDefault status
unaffected
Any version before 2025-06-27
affected
Description
Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to all cloud instances.
Problem types
CWE-290 Authentication Bypass by Spoofing
Product status
Any version before 2025-06-27
References
www.yealink.com/...-unauthorized-access-to-rps-vulnerability
www.yealink.com/...urity_Remediation_Verification_Report.pdf
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.