Executive brief
Yealink Device Management (DM) version 3.6.0.20 is vulnerable to an unauthenticated command injection vulnerability via the /sm/api/v1/firewall/zone/services URI. An attacker can exploit this to execute commands as root, potentially leading to full system compromise.
Affected products
- Yealink Device Management (DM) 3.6.0.20
Timeline
- 2021-10-15: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog