Описание
The Yealink YMCS RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.
The Yealink YMCS RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-52917
- https://dnip.ch/2025/06/25/yealink-voip-phones-insecurity-by-design
- https://seclists.org/fulldisclosure/2025/Jun/20
- https://support.yealink.com/en/portal/knowledge/show?id=6476e7cd6a27da76bd06a9c9
- https://www.yealink.com/en/trust-center/security-advisories/f8205560a8c7443f
Связанные уязвимости
CVSS3: 4.3
nvd
8 месяцев назад
The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.