Junglewise Threat Intelligence

CVE-2026-7208: Yealink SIP-T33G race condition in diagnostic file deletion

CVE-2026-7208 · Severity: medium · CVSS 5.3 · Published 2026-09-14

Vendors: Yealink.

Executive brief

The Yealink SIP-T33G is a business IP phone used in corporate communications infrastructure. A race condition in its firmware allows authenticated attackers to interrupt active diagnostic processes by deleting temporary files used during operations like ping or traceroute, causing the system to enter an inconsistent state. This can disrupt network troubleshooting and potentially leave the device in an error condition.

Technical details

This vulnerability is a race condition (CWE-362) in the firmware's diagnostic module where output files are written to predictable paths. An authenticated attacker can exploit a window of time between when a diagnostic process (e.g., traceroute, ping) is initiated and when it completes, by simultaneously invoking a file deletion endpoint to remove the temporary output files. The predictable file paths and lack of proper synchronization allow the attacker to reliably interrupt the process and leave the system in an inconsistent state. The attack requires authentication and is triggered via network access. Firmware versions 124.86.x.x prior to 124.87.0.0 are affected; upgrading to 124.87.0.0 or later resolves the issue.

Affected products

  • Yealink SIP-T33G 124.86.x.x prior to 124.87.0.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fix available in firmware version 124.87.0.0

References