Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2021-27561

Yealink | Device ManagementAdded 2021-11-03Remediation Deadline 2021-11-17

Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-78

References