Yealink RPS Unauthorized Access Vulnerability Allowing Information Disclosure
Vulnerability
A vulnerability in Yealink RPS, prior to June 27, 2025, allows unauthorized access to sensitive information, including AutoP URL addresses. This issue arises from a lack of proper authentication, leaving the system open to third-party spoofing attacks. Yealink has addressed this vulnerability by implementing an enhanced multi-factor verification mechanism for identity authentication, which has been automatically deployed to all cloud service instances.
Impact
Exploitation of this vulnerability could lead to unauthorized retrieval of AutoP URLs, potentially allowing for further attacks or information misuse.
Remediation
Yealink has released a security update that includes an enhanced multi-factor verification mechanism for identity authentication. This update has been automatically deployed to all cloud service instances.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
