CVE-2025-66738High· 8.8▾ TwilightAn issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
sip-t21(p)e2_firmware = 52.84.0.15Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66737Medium· 4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal
CVE-2025-15131Medium· 6.3A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024
CVE-2025-15132Medium· 6.3A vulnerability was determined in ZSPACE Z4Pro+ 1.0.0440024
CVE-2025-11523Medium· 6.3A vulnerability was detected in Tenda AC7 15.03.06.44
CVE-2025-59834Critical· 9.8ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0