Junglewise Threat Intelligence

CVE-2021-27561: Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

CVE-2021-27561 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Yealink.

Executive brief

Yealink Device Management (DM) version 3.6.0.20 is vulnerable to an unauthenticated command injection vulnerability via the /sm/api/v1/firewall/zone/services URI. An attacker can exploit this to execute commands as root, potentially leading to full system compromise.

Affected products

  • Yealink Device Management (DM) 3.6.0.20

Timeline

  • 2021-10-15: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog