Skip to content
COOEY

FAIL › dossier

yealink

VENDOR

· dossier confidence 50%

Yealink's security posture is compromised by a history of critical and high-severity vulnerabilities in its device management and web interfaces, with at least one actively exploited in the wild.

PROFILE
CategorytelecommunicationsWhat they doYealink manufactures IP phones, video conferencing systems, and unified communications devices for enterprise and small business markets.
SECURITY POSTURE

The company has experienced critical and high-severity vulnerabilities in its device management and web interfaces, with at least one actively exploited in the wild.

Notable failures
  • CVE-2021-27561: unauthenticated SSRF enabling RCE in Device Management
  • CVE-2024-33109: directory traversal allowing arbitrary file overwrite in Tiptel IP 286 web interface
Patterns: unpatched edge-device RCEs; directory traversal in web interfaces
Reputationsevere-fallout (+0.00) · 1 trusted sources Coveragecooey
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-27561 high Yealink Device Management suffered an unauthenticated SSRF vulnerability enabling remote code execution, now actively exploited in the wild.
2024-09-19 CVE-2024-33109 critical Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Unauthenticated RCE via SSRF is a critical flaw with severe fallout, though the provided source is purely factual without sentiment.
cooey ↗severe-fallout+0.00
neutral
"Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution."
Open questions: What is the exact founding year of Yealink? · What is the exact headquarters location of Yealink? · What is the exact size of Yealink? · What is the exact ownership structure of Yealink? · What is the exact website URL of Yealink?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-29 04:12:39.465640+00:00