sip-t21(p)e2_firmware vulnerabilities
CVEs whose affected-version data names the sip-t21(p)e2_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-66738High· 8.8An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
▾ Twilightyealink · sip-t21(p)e2_firmwareEPSS 0.63%via NVD
CVE-2025-66737Medium· 4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal
Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.
▾ Sunlityealink · sip-t21(p)e2_firmwareEPSS 0.66%via NVD