CRITICAL

CVE-2021-27561

Yealink Device Management 2021-10-15 CVSS v3.1
CVSS
9.8
KEV

Description

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

Summary dbcve.org

Yealink Device Management version 3.6.0.20 contains an unauthenticated command injection vulnerability in the /sm/api/v1/firewall/zone/services API endpoint. Attackers can inject arbitrary OS commands through this URI and execute them with root privileges, enabling complete system compromise without any authentication credentials.

Mitigation

Upgrade Yealink Device Management to a patched version immediately. If an immediate upgrade is not feasible, restrict network access to the management interface using firewall rules or network segmentation to prevent unauthenticated external access.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

82.87%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE