Skip to content
COOEY

EXPOSURES › CVE-2021-27561

CVE-2021-27561

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27561 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Yealink Device Management suffered an unauthenticated SSRF vulnerability enabling remote code execution, now actively exploited in the wild.

The Yealink Device Management server contained an SSRF flaw allowing unauthenticated remote code execution, a critical failure for any organization relying on Yealink for device management. This vulnerability is actively exploited in the wild, indicating a severe compliance and security risk for DIB vendors using Yealink hardware. Organizations must immediately patch or replace affected devices and assess their exposure to active exploitation.

Shame score — The vulnerability allows unauthenticated remote code execution and is actively exploited in the wild, representing a severe, avoidable security failure that compromises device management integrity.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Unauthenticated RCE via SSRF is a critical flaw with severe fallout, though the provided source is purely factual without sentiment.
cooey ↗ severe-fallout +0.00
neutral
"Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.