FAIL › dossier
yealink
VENDOR· dossier confidence 50%
Yealink's security posture is compromised by a history of critical and high-severity vulnerabilities in its device management and web interfaces, with at least one actively exploited in the wild.
PROFILE
CategorytelecommunicationsWhat they doYealink manufactures IP phones, video conferencing systems, and unified communications devices for enterprise and small business markets.
SECURITY POSTURE
The company has experienced critical and high-severity vulnerabilities in its device management and web interfaces, with at least one actively exploited in the wild.
Notable failures
- CVE-2021-27561: unauthenticated SSRF enabling RCE in Device Management
- CVE-2024-33109: directory traversal allowing arbitrary file overwrite in Tiptel IP 286 web interface
Patterns: unpatched edge-device RCEs; directory traversal in web interfaces
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-27561 | high | Yealink Device Management suffered an unauthenticated SSRF vulnerability enabling remote code execution, now actively exploited in the wild. |
| 2024-09-19 | CVE-2024-33109 | critical | Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Unauthenticated RCE via SSRF is a critical flaw with severe fallout, though the provided source is purely factual without sentiment.
neutral
"Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution."
Open questions: What is the exact founding year of Yealink? · What is the exact headquarters location of Yealink? · What is the exact size of Yealink? · What is the exact ownership structure of Yealink? · What is the exact website URL of Yealink?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-29 04:12:39.465640+00:00