yealink has 3 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 5.3 (medium). Most affected products: sip-t21(p)e2_firmware (2), SIP-T33G (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Worst active — by depth score
CVE-2025-66738High· 8.8An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.49CVE-2026-7208Medium· 5.3Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predic…29CVE-2025-66737Medium· 4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal24
yealink vulnerabilities
CVEs affecting yealink, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-7208Medium· 5.3Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predic…
Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predic…
CVE-2025-66738High· 8.8An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
CVE-2025-66737Medium· 4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal
Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.