Junglewise Threat Intelligence

CVE-2025-66738: Yealink T21P_E2 command injection in diagnostic ping function

CVE-2025-66738 · Severity: high · CVSS 8.8 · Published 2025-12-26

Vendors: Yealink.

Executive brief

A security vulnerability exists in Yealink T21P_E2 VoIP phones that could allow an authorized user to take full control of the device. By sending a specially crafted request to the phone's diagnostic tools, an attacker can execute unauthorized commands. This could lead to eavesdropping on calls, disruption of phone services, or using the device as a foothold to attack other parts of the corporate network.

Technical details

A command injection vulnerability (CWE-77) exists in the Yealink T21P_E2 phone running firmware version 52.84.0.15. The flaw is located within the ping function of the diagnostic component, which fails to properly neutralize special elements in user-supplied input. A remote attacker with 'normal' (low) privileges can exploit this by sending a crafted request to the web management interface. Successful exploitation allows for arbitrary code execution with the privileges of the web service, potentially leading to full system compromise. A proof-of-concept has been identified in public disclosures.

Affected products

  • Yealink T21P_E2 Phone 52.84.0.15

Timeline

  • 2025-12-26: disclosed
  • 2025-12-26: advisory

References

Related threats