Yealink manufactures a focused line of business IP telephony and communications devices, with its vulnerability footprint concentrated in a small set of widely deployed SIP phone models such as the T38G and T41P series and their firmware. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code availability, reflecting the exposed network and web-management interfaces typical of unified communications appliances. The exposure recurs through weakness classes including path traversal, OS command injection, cross-site scripting, and insecure sensitive-information storage—patterns endemic to embedded device management and call-control processing. Defenders should prioritize patch deployment for these devices in border and internal telephony networks and restrict administrative access; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yealink over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27561CRITICAL Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | Oct 15, 2021 | 9.8 | 96 | YES | YES |
CVE-2013-5758HIGH cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demon | Aug 3, 2014 | 9.0 | 45 | NO | YES |
CVE-2013-5755HIGH config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) va | Jul 16, 2014 | 10.0 | 41 | NO | YES |
CVE-2025-66738HIGH An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic componen | Dec 26, 2025 | 8.8 | 31 | NO | NO |
CVE-2024-33109CRITICAL Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload fu | Sep 19, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-24681CRITICAL An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used t | Feb 23, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-43959HIGH An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component. | Oct 17, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-16218HIGH A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote attacker to trigger code execut | May 29, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-16217HIGH The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker to trigger OS commands or open a | May 29, 2019 | 8.8 | 27 | NO | NO |
CVE-2024-24091CRITICAL Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface. | Feb 8, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yealink.
Media articles that mention a CVE ID that affects a product developed by Yealink — matched by CVE ID, not by vendor name.