Yealink RPS Unauthorized Access Vulnerability Allowing Information Disclosure

Vulnerability

A vulnerability in Yealink RPS, prior to June 27, 2025, allows unauthorized access to sensitive information, including AutoP URL addresses. This issue arises from a lack of proper authentication, leaving the system open to third-party spoofing attacks. Yealink has addressed this vulnerability by implementing an enhanced multi-factor verification mechanism for identity authentication, which has been automatically deployed to all cloud service instances.

Impact

Exploitation of this vulnerability could lead to unauthorized retrieval of AutoP URLs, potentially allowing for further attacks or information misuse.

Remediation

Yealink has released a security update that includes an enhanced multi-factor verification mechanism for identity authentication. This update has been automatically deployed to all cloud service instances.

Added: Dec 21, 2025, 4:18 AM
Updated: Dec 21, 2025, 4:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
1.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.