Yeastar manufactures telecommunications gateway and IP PBX appliances such as the N412, N824, and NeoGate TG400 product lines, which bridge legacy telephony systems with VoIP networks in enterprise and small-business deployments. The recurring vulnerability signal centers on firmware and configuration issues affecting these embedded devices, notably path-traversal weaknesses that expose filesystem access and weak password-hashing implementations that reduce cryptographic resilience against offline attack. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yeastar over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27328MEDIUM Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or dec | Feb 19, 2021 | 6.5 | 26 | NO | NO |
CVE-2022-47732HIGH In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing admin hash, allowing, once cracked, to log | Jan 20, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yeastar.
Media articles that mention a CVE ID that affects a product developed by Yeastar — matched by CVE ID, not by vendor name.