Executive brief
A security vulnerability exists in Yealink T21P_E2 VoIP phones that could allow an authorized user to take full control of the device. By sending a specially crafted request to the phone's diagnostic tools, an attacker can execute unauthorized commands. This could lead to eavesdropping on calls, disruption of phone services, or using the device as a foothold to attack other parts of the corporate network.
Technical details
A command injection vulnerability (CWE-77) exists in the Yealink T21P_E2 phone running firmware version 52.84.0.15. The flaw is located within the ping function of the diagnostic component, which fails to properly neutralize special elements in user-supplied input. A remote attacker with 'normal' (low) privileges can exploit this by sending a crafted request to the web management interface. Successful exploitation allows for arbitrary code execution with the privileges of the web service, potentially leading to full system compromise. A proof-of-concept has been identified in public disclosures.
Affected products
- Yealink T21P_E2 Phone 52.84.0.15
Timeline
- 2025-12-26: disclosed
- 2025-12-26: advisory