---
id: CVE-2026-7208
title: >-
  Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a
  race condition vulnerability that allows authenticated attackers to interrupt
  active diagnostic processes by concurrently deleting output files written to
  predic…
summary: >-
  Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a
  race condition vulnerability that allows authenticated attackers to interrupt
  active diagnostic processes by concurrently deleting output files written to
  predic…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-362
vendor: Yealink
product: SIP-T33G
affected:
  - SIP-T33G >= 124.86.0.0 < 124.87.0.0
published: '2026-09-14'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:28:01.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7208'
references:
  - url: >-
      https://www.vulncheck.com/advisories/yealink-sip-t33g-race-condition-via-diagnostic-file-deletion
    label: disclosure@vulncheck.com
  - url: 'https://www.yealink.com/en/product-detail/ip-phone-t33g'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.yealink.com/en/trust-center/security-bulletins/race-condition-on-runtime-diagnostic-files-in-yealink-sipt33g
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00347
epssPercentile: 0.2543
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T16:14:31.597209Z'
ingestedAt: '2026-09-14T15:23:07.422Z'
---

## Overview

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predictable paths under the diagnostic directory. Attackers can trigger a diagnostic operation such as traceroute or ping and simultaneously invoke the file deletion endpoint to terminate the running process, leaving the system in an inconsistent state.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
