EXPOSURES › CVE-2021-27561
CVE-2021-27561
HIGH ⌖ ON CISA KEV · EXPLOITEDYealink Device Management suffered an unauthenticated SSRF vulnerability enabling remote code execution, now actively exploited in the wild.
The Yealink Device Management server contained an SSRF flaw allowing unauthenticated remote code execution, a critical failure for any organization relying on Yealink for device management. This vulnerability is actively exploited in the wild, indicating a severe compliance and security risk for DIB vendors using Yealink hardware. Organizations must immediately patch or replace affected devices and assess their exposure to active exploitation.
Shame score — The vulnerability allows unauthenticated remote code execution and is actively exploited in the wild, representing a severe, avoidable security failure that compromises device management integrity.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.
"Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution."