Vulnerabilities (CVE)

Filtered by vendor Yealink Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24113 1 Yealink 2 W60b, W60b Firmware 2023-08-28 N/A 9.1 CRITICAL
Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).
CVE-2021-27561 1 Yealink 1 Device Management 2023-08-08 10.0 HIGH 9.8 CRITICAL
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.