Junglewise Threat Intelligence

CVE-2025-66737: Yealink T21P_E2 directory traversal in diagnostic component

CVE-2025-66737 · Severity: medium · CVSS 4.3 · Published 2025-12-26

Vendors: Yealink.

Executive brief

Yealink T21P_E2 IP phones, commonly used for business telecommunications, contain a security flaw in their diagnostic tools. An authorized user on the network can exploit this to access sensitive internal system files that should normally be restricted. This could lead to the exposure of configuration details or other private device information.

Technical details

A directory traversal vulnerability (CWE-23) exists in the diagnostic component of Yealink T21P_E2 IP phones running firmware version 52.84.0.15. The flaw resides in the 'result read' function, which fails to properly sanitize user-supplied input paths. An authenticated attacker with 'normal' privileges can send a specially crafted network request to bypass directory restrictions and read arbitrary files from the underlying operating system. While the attack requires valid credentials, it allows for the unauthorized retrieval of sensitive system information. A proof-of-concept has been identified in public disclosures.

Affected products

  • Yealink SIP-T21(P) E2 firmware 52.84.0.15

Timeline

  • 2025-12-26: disclosed: Initial NVD publication
  • 2025-12-27: other: CISA-ADP assessment and SSVC enrichment added

References

Related threats