Yealink Device Management Platform... CVE-2021-27561 CVE-2021-27562

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# SSD Advisory - Yealink DM Pre Auth 'root' level RCE February 23, 2021 [SSD Disclosure / Noam Rathaus](https://ssd- disclosure.com/author/noamr/ "Posts by SSD Disclosure / Noam Rathaus") [Uncategorized](https://ssd-disclosure.com/category/uncategorized/) **TL;DR** Find out how multiple vulnerabilities in Yealink DM (Device Management) allow an unauthenticated attacker to run arbitrary commands on the server with root privileges. **Vulnerability Summary** [Yealink DM](https://www.yealink.com/products_108.html) (Device Management) platform - "offers a comprehensive management solution with key features Unified Deployment and Management, Real-Time Monitoring and Alarm, Remote Troubleshooting. Several vulnerabilities in the Yealink DM server allow remote unauthenticated attackers to cause the server to execute arbitrary commands due to the fact that user provided data is not properly filtered. **CVE** CVE-2021-27561 and CVE-2021-27562 ****Credit**** Two independent security...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息