CRITICAL
CVE-2021-27561
CVSS
9.8
KEV
Description
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
Summary dbcve.org
Yealink Device Management version 3.6.0.20 contains an unauthenticated command injection vulnerability in the /sm/api/v1/firewall/zone/services API endpoint. Attackers can inject arbitrary OS commands through this URI and execute them with root privileges, enabling complete system compromise without any authentication credentials.
Mitigation
Upgrade Yealink Device Management to a patched version immediately. If an immediate upgrade is not feasible, restrict network access to the management interface using firewall rules or network segmentation to prevent unauthenticated external access.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
82.87%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.